Clauzy ← Legal documents

Security Policy

Version 1.6 · Last updated 2026-09-04 · legal@clauzy.ai

This Policy describes the technical and organizational measures Prestance Lab applies to protect Customer Data processed through the Services. It is referenced from Prestance Lab's General Terms and Conditions and from the Data Processing Agreement, and reflects the safeguards in place across our infrastructure, encryption, access-control, and AI processing layers.

1. Overview

Prestance Lab operates a multi-tenant Software-as-a-Service platform that processes voice and text data generated during sales-advisor rehearsal drills (simulated client conversations). This document summarizes the technical and organizational measures (the "TOMs") we apply to safeguard Customer Data, in alignment with the commitments set out in our General Terms and Conditions and our Data Processing Agreement.

2. Hosting and infrastructure

The Services are operated on independently audited, enterprise-grade infrastructure providers. Core infrastructure — database, application runtime, and media transport — is pinned to the European Union; the AI inference providers and their respective countries of processing are itemized below and in the DPA, §7.

Database & backend
EU-hosted PostgreSQL with daily encrypted backups and point-in-time recovery. Hosting region: Ireland (EU, AWS eu-west-1). Provider listed in the DPA, §7.
Application backend
EU-hosted application runtime serving the API and the voice-agent worker. Hosting region: Falkenstein (EU).
Voice transport
WebRTC SFU operated in EU region (eu-central), end-to-end-encrypted in transit via DTLS-SRTP. Provider listed in the DPA.
Real-time voice AI
Live-drill voice-to-voice, coach, and intro-briefing voice synthesis run on our real-time voice provider's infrastructure in the United States (no EU data residency), accessed under a signed Enterprise Data Processing Agreement with Standard Contractual Clauses. Provider and transfer mechanism listed in the DPA, §7.
Coaching-pipeline model (proprietary)
Post-drill analysis runs on our proprietary model, self-hosted on Nebius cloud infrastructure under a signed Data Processing Agreement. Processed in the European Union. Provider listed in the DPA, §7.

Prestance Lab contracts only with sub-processors that hold independent third-party security audits. The complete sub-processor list — including entity name, country of processing, transfer mechanism, and DPA link — is maintained in the Data Processing Agreement.

3. Encryption

In transit

TLS 1.2 or higher is enforced on all application, database, and API connections. Voice sessions use WebRTC with DTLS-SRTP, providing end-to-end-encrypted audio transport between the advisor's device and the Prestance Lab worker.

At rest

All persistent data — database rows, object storage, backups, and the advisor-memory store on our own application server — is encrypted at rest using AES-256. For the managed stores, keys are managed by the provider in HSM-backed key-management services; the advisor-memory store is additionally reachable only over the server's private network, with no public database port.

4. Access control

Prestance Lab enforces a three-layer access-control model:

  1. Application layer — role-based UI access (Advisor, Manager, Admin), enforced at the routing layer.
  2. API layer — every endpoint requires a JWT (ES256, issued by Supabase Auth) and is validated against an explicit allow-list of claims.
  3. Database layer — Row-Level Security (RLS) policies on the tables that hold Authorized-User content (drill sessions, coach sessions, personas, and workspace files) enforce strict workspace and user isolation on the user-facing paths. The backend's own service connections sit outside RLS by design, are used only by Prestance Lab's server-side services, and are never exposed to clients.

Drill sessions are private to the advisor: transcripts, recordings, scores, and coaching letters are readable by the advisor only. Managers receive aggregated activity counts and recurring patterns — never a recording, a transcript, a practice score, or an individual's words. No Outputs are exported to the Customer's HR systems by Prestance Lab.

HR use of Outputs is restricted

Managers receive aggregated signals only; per-advisor transcripts, recordings, and practice scores are not surfaced to them. The Customer is responsible for ensuring those Outputs are not used as the sole or principal basis for any HR decision, as the basis for automated decision-making within the meaning of Article 22 GDPR, or to infer special-category data within the meaning of Article 9 GDPR. The substantive prohibition is set out in our Acceptable Use Policy §4.

5. AI and data privacy

No training by sub-processors on Customer Data

Post-drill analysis runs on our proprietary model, self-hosted on Nebius cloud infrastructure: for post-drill analysis, no third-party model provider processes Customer Data, and nothing is trained on it. The real-time voice provider is accessed via a paid Enterprise tier under explicit no-training contractual terms, namely the Google Cloud Service Specific Terms, under which Customer Data is not used to train Google's foundation models. Advisor speech-to-text runs on ElevenLabs under enterprise no-training, zero-retention terms, as recorded in the DPA, §7.

Temporary retention for abuse monitoring

Temporary retention for abuse monitoring at the provider level may apply (typically ≤ 30 days). Sub-processors may apply human review to content flagged by automated abuse-monitoring systems, in accordance with each provider's published policy. Prestance Lab does not control this review and surfaces the relevant provider policies in the DPA.

Voice recordings

Voice recordings are created by Prestance Lab's worker via the LiveKit Egress API and uploaded directly to a Prestance Lab-controlled storage bucket. Recording retention is governed by the Customer's Order Form and the Data Processing Agreement. Voice recordings are anonymized and de-identified before they are stored; retained practice audio is not linkable to an identifiable person.

Data residency

Core infrastructure data paths are pinned to EU regions: Supabase Ireland (database, authentication, object storage), Hetzner Falkenstein (application and voice-agent worker), and LiveKit eu-central (Frankfurt, media transport). Two AI processing activities take place in the United States under Standard Contractual Clauses: real-time voice-to-voice synthesis (Google — the live-drill voice-to-voice, coach, and intro-briefing provider) and advisor speech-to-text (ElevenLabs — enterprise zero-retention terms), with no EU data residency. Post-drill coaching analysis runs on our proprietary model, self-hosted on Nebius infrastructure in the European Union under a signed Data Processing Agreement. A limited set of observability and abuse-monitoring metadata may additionally transit to the United States at the vendor level. The provider, country of processing, and transfer mechanism for each are disclosed in the Data Processing Agreement, §7.

6. Data ownership and retention

7. Sub-processors

The complete list of sub-processors, including activity, country of operation, and transfer mechanism, is maintained in the Data Processing Agreement. Changes to the list are notified to active Customers in accordance with the procedure described therein.

8. Operational security

Account hygiene

All Prestance Lab corporate accounts use multi-factor authentication. API keys are rotated on personnel change and on any suspected exposure.

Personnel and contractors

Prestance Lab maintains an internal Acceptable Use Policy binding all employees, interns, and contractors with access to Prestance Lab systems, code, or Customer Data. It covers device security, credential handling, approved tooling for work on Customer Data, and offboarding. Contractors acknowledge it in writing as a condition of access and remain subject to it for the duration of the engagement.

Secrets management

Production secrets are held in 1Password vaults, loaded into the deploy job environment, and passed by the deploy tooling to the application containers at deploy time; they are never committed to source control.

Patching

Dependencies and base images are kept current as part of normal development. Critical vulnerabilities are patched within 7 days of public disclosure.

Backups

PostgreSQL backups are taken daily and stored encrypted, with a retention period of 30 days. Point-in-time recovery is available to a granularity of 5 minutes within the preceding 7 days.

Incident response

A documented runbook covers detection, containment, eradication, recovery, and post-incident review. Personal Data Breaches are notified to the Customer without undue delay, in accordance with the Data Processing Agreement.

9. Compliance posture

GDPR

Prestance Lab processes personal data under GDPR-aligned contracts: EU hosting is in effect; a Data Processing Agreement is executed with each Customer; sub-processor DPAs are in place; Standard Contractual Clauses apply to any non-EU sub-processor transfer.

EU AI Act

Prestance Lab acts as the provider of the Solution within the meaning of the EU AI Act and complies with the provider obligations under Articles 25 et seq. The Solution does not perform emotion recognition in the workplace within the meaning of Article 5(1)(f).

SOC 2

Prestance Lab is actively working toward SOC 2 Type I readiness and intends to begin a formal observation period; a formal observation period has not yet started. All infrastructure sub-processors hold an independent third-party audit (SOC 2 Type II or ISO/IEC 27001).

10. Reporting a security concern

11. Updates to this Policy

In accordance with GTC §2.7, Prestance Lab may update this Policy. Material changes will be notified to active Customers at least 30 days in advance, unless a shorter timeframe is required by law or to address a material security risk.