Security

What we do about your data.

This is the one answer for every product we run: After Hours AI, AI Executive, TopRated, and CustomerLedger itself, which is the customer record underneath all of them. One page, kept current, measured where a machine can measure it, and plain about what is not finished. If someone asks you what we do about security, send them here.

The short version

Eight things we can say today.

Encrypted at rest and in transit

The servers we operate use full-disk encryption. Every domain we run sits behind Cloudflare, so traffic between you and us is TLS end to end.

Backed up hourly, offsite daily

Local versioned snapshots run every hour. Once a day the whole set is encrypted to a key whose private half is not on the machine, then copied offsite. A stolen or destroyed server exposes nothing readable.

Each client is a separate file

Your customers live in a database file that belongs to you alone. Another business using this software is a different file, not a different row. There is no shared table to filter and therefore no filter to get wrong.

Consent in the customer's own words

When someone says yes to being texted, we store the exact wording they agreed to and the date. Before an outbound text leaves on the gated path, that record is checked, and an unreadable record blocks the send rather than allowing it.

No call audio is kept

Calls are transcribed as they happen. The transcript is what your AI works from and what you can read afterward. The audio is not stored.

Never trained on, never sold

We do not use your data, your customers, your calls or your uploads to train any model, and we do not sell or share it with third parties for their marketing.

You can pause your AI, instantly

Every AI we run for a customer has a pause control on its own desk that only its owner can operate. Paused means it stops replying, and the messages it would have answered are held and logged for you to see.

Sign-in by magic link or PIN

Owners sign in with a one-time emailed link or a PIN. Where a password is offered at all it is optional and stored only as a salted hash. Sessions live on our side and can be revoked by us at any time.

Where your data lives

On infrastructure we operate, in the United States.

We do not rent a multi-tenant SaaS database. Your record is held on servers we run ourselves, encrypted at the disk, reachable only through Cloudflare's edge, and never exposed directly to the internet. That is a smaller surface than a cloud console with forty services enabled, and it is also a smaller team, which is why the backups above and the offsite copy exist.

Payments are handled by Stripe. Card numbers are entered on Stripe's pages and never pass through ours; we hold a customer id and a subscription status, nothing more.

If you connect a Google account so your AI can read a calendar or draft mail, we hold the OAuth token for that account and nothing else. Disconnecting deletes our copy of the token. It does not yet call Google's revoke endpoint on your behalf; revoking at Google's own permissions page is the belt to that suspender, and we say so because a page that omitted it would be lying by absence.

What your AI can and cannot do

It answers. It does not act behind your back.

The AI that picks up your phone or your texts is built to answer people, not to run commands. Customer-facing agents are launched with no tools at all: no file access, no shell, no way to reach any other client's record, whatever a caller says to them. That was verified in both directions on 2026-09-01, with a benign prompt that used to work and now does not.

Anything that leaves your control is gated. Texts go through the consent check above. Email your AI writes for you is drafted, and you send it. Public visitors talking to your AI get its public knowledge only; the owner's private notes are stripped by the server before a reply is built, not hidden by the prompt.

Who sees what SHADOW

Stamped at write time, or rejected.

You own the whole relationship, so you see it whole. Each business, and each agent answering for it, sees the part it captured. Every fact is stamped at the moment it is written with the brand that captured it and the audience allowed to see it. An unstampable write is a rejected write. Audiences are constructed from the tenant and the brand rather than assembled by whoever is building a prompt that day, which is the difference between a rule and a habit.

Fact classAgent, own brandAgent, sibling brandOperator
Business identityWith own historyAbsentFull
Consent evidenceDecisions onlyNeverFull
Cross brand factsAbsentAbsentFull
NameSpoken above 0.8 confidenceAbsentFull
Operator notesNeverNeverFull
How hard this has been exercised

3 of 548 rows carry the operator audience and the rest are brand scoped. The mechanism is real and lightly exercised, and a claim resting on 3 rows should be read as one resting on 3 rows.

Peer tenancy LIVE

Your clients are not your contacts.

There is a second, harder wall in the design, between you and the businesses you run software for. The design is one file per tenant, so the same phone number in two tenants would be two unlinked people, permanently and by design, and a canary planted in either tenant must appear in zero prompts built for the other.

The distinction matters and is easy to blur. Cross-business visibility above is your view of your customer across your businesses. It is not a claim that unrelated companies using this software can see each other's people. They cannot, and the mechanism for that is separation at the file level rather than a filter on a query.

measured 2026-09-02 | tenants in the control plane: 7 | state LIVE

Third parties

Who else touches your data, and for what.

Each of these sees only the slice it needs to do its job. None of them is allowed to use your data for its own purposes under the terms we hold with them.

ProviderWhat it doesWhat it sees
CloudflareDNS, TLS, edge, static hosting for this siteTraffic in flight
TelnyxPhone numbers, calls, and text messagesCall audio in flight, message text, phone numbers
DeepgramSpeech to text on live callsCall audio in flight
ElevenLabsText to speech for your AI's voiceThe words your AI says
AnthropicThe language model behind every AI we runThe conversation and the knowledge it is handed
StripeBillingCard and payment details, which we never see
GoogleCalendar and mail, only if you connect them; encrypted offsite backup storageWhat you connected; ciphertext only for backups
FirebaseStatic hosting for aiexec.mePage views
What we do not claim

Read this part too.

We do not hold a SOC 2 report. We have not yet had an outside firm attack the system, though we run our own reviews and publish what they find in the changelog. We are a small company, and one operator holds write access to the store, which is exactly why every write is stamped with who made it and the append-only tables are hash chained so a change after the fact is detectable. Detectable is the word. Nothing here is proof against a determined insider with the keys, and we would rather you know that than read a claim the design cannot back.

The chain check is run at every build of this site rather than typed in. As of 2026-09-02, 0 of 4 chained tables fail verification. When that number is not zero, the architecture page says which one and why, and the state chip on it stays where the measurement puts it.

Consent decisions are evaluated today against the operator's ledger rather than inside each client's own file, so the consent record is shared across the businesses we run while the customer records themselves are not. Moving that check into the client file is on the build list and this sentence will change when it lands.

Self-serve deletion is not built yet. Today deletion is by request, and we do it by hand within 30 days. A per-person and per-tenant purge that leaves a logged erasure on the chain is on the build list, and this paragraph will change when it ships.

Your controls, and how to reach us

Ask, and we answer.

Pause, disconnect, export, delete

Pause your AI from its desk. Disconnect Google from the same place. For an export or a deletion of what we hold about you or your customers, write to [email protected] from the address on your account, and we do it within 30 days.

Found a problem?

If you believe you have found a security issue in anything we run, tell us at [email protected] with what you saw and how to reproduce it. We answer every report, we fix what is real, and we will not pursue anyone who reports in good faith.