Skip to content

Security and governance

AIRoster talks to your customers, so it is built to be inspected: disclosed AI, scoped roles, server-side enforcement and exportable data.

Disclosure by default

AI callers introduce themselves as AI at the start of every conversation, outbound and inbound. This is not a setting a rushed afternoon can switch off.

Verified businesses only

Before Peach goes live, we confirm you actually represent the business: a code sent by text, call or email to a contact method the business publishes on its own website. It is why nobody can set Peach up in your name, and why it takes a minute rather than nothing at all.

Role-scoped access

Owner, manager and agent roles control who can change policy, edit leads and manage billing. Team invitations are email-verified.

Server-side authority

Every request is authenticated and re-checked on the server. Plan entitlements, metering and permissions cannot be altered from a browser or a phone.

Data isolation

Workspace data is isolated per organisation with row-level security in the database, not just filters in the interface.

GDPR controls

Workspace data export and deletion requests are self-serve, in line with UK GDPR. Recordings and transcripts stay under your control.

Guarded public surface

Public endpoints such as the website widget are rate-limited and validated server-side to keep junk and abuse out of your pipeline.

Formal certifications (such as SOC 2 or ISO 27001) are not yet in place and we will not claim them until they are. Security questionnaires are welcome via the contact page.