Security and governance
AIRoster talks to your customers, so it is built to be inspected: disclosed AI, scoped roles, server-side enforcement and exportable data.
Disclosure by default
AI callers introduce themselves as AI at the start of every conversation, outbound and inbound. This is not a setting a rushed afternoon can switch off.
Verified businesses only
Before Peach goes live, we confirm you actually represent the business: a code sent by text, call or email to a contact method the business publishes on its own website. It is why nobody can set Peach up in your name, and why it takes a minute rather than nothing at all.
Role-scoped access
Owner, manager and agent roles control who can change policy, edit leads and manage billing. Team invitations are email-verified.
Server-side authority
Every request is authenticated and re-checked on the server. Plan entitlements, metering and permissions cannot be altered from a browser or a phone.
Data isolation
Workspace data is isolated per organisation with row-level security in the database, not just filters in the interface.
GDPR controls
Workspace data export and deletion requests are self-serve, in line with UK GDPR. Recordings and transcripts stay under your control.
Guarded public surface
Public endpoints such as the website widget are rate-limited and validated server-side to keep junk and abuse out of your pipeline.
Formal certifications (such as SOC 2 or ISO 27001) are not yet in place and we will not claim them until they are. Security questionnaires are welcome via the contact page.