Security & compliance
Built for the CISOs who have to sign it.
Aelo handles sales conversations — often your most sensitive data. Here's exactly how we protect it.
Encryption
- TLS 1.2+ in transit
- AES-256 at rest
Hosting & region
- Customer content is stored at rest in the EU
- Cloudflare Workers execute at the edge nearest the request, so processing may occur outside the EU
- Vendor access, locations and transfer safeguards are listed in our public sub-processor register
PII handling
- For new transcripts on current write paths, supported phone, email, payment-card and valid IBAN patterns are redacted on write and before model analysis; original audio and earlier rows are unchanged
- Retention you control: 1 to 365 days, 1 year by default
- DSR request intake, review and status tracking
- Approved DSRs use the applicable product or support procedure; execution is not automatic
Access control
- Four organization roles plus three project roles
- Organization and project scoping enforced in RBAC
- API keys bound to one organization, with read and write granted separately
- Keys stored hashed — the plaintext is shown once, never stored, and revoking one takes effect on the next request
Compliance support
- Public DPA and sub-processor register
- Customer-configurable retention: 1 to 365 days
- DSR request intake, review and status tracking
- Public privacy policy describing Controller and Processor roles
Sub-processors
- OpenAI — transcript analysis; ElevenLabs / Deepgram — speech-to-text
- Cloudflare — hosting, CDN, storage
- Stripe — payments for our own billing; card details never touch Aelo
- Full list: sub-processors page
DPA
Data Processing Agreement
Our DPA is published on this site. It covers Controller and Processor roles, technical measures and transfer mechanisms. The public sub-processor register lists each provider, purpose, location and safeguard.
Security questions? security@aelo.cloud