SECURITY AND TRUST

Enterprise data protection, documented

UpTroop runs daily practice for frontline teams at enterprise scale, including voice conversations. This page sets out UpTrop's information security & data policy.

CORE CONTROLS

How your data is protected

Encryption

Data encrypted in transit with TLS 1.2 or higher, and at rest with AES-256.

Access control

Role-based access for administrators, managers and learners. Least-privilege internal access, reviewed periodically, with audit logging of administrative actions.

Data residency

Hosting region is selected per deployment. US customer data can be hosted in a US region.

Authentication

Learners join through a one-time passcode on their existing channel — no shared credentials and no personal email required. SSO/SCIM available for user & administrator accounts.

Tenant isolation

Each customer tenant is physically separated. Your content, scenarios and learner records are never used to train models for another customer.

Business continuity

Automated backups with defined recovery objectives, and monitored uptime.

VOICE AND CONVERSATION DATA

Practice is voice-based. Here is what that means for your data.

Voice raises the bar on privacy review, so we state this plainly rather than leaving it to the DPA.

What is captured

Practice sessions between a learner and an AI partner. These are simulations, not recordings of real customers, so no customer PII enters the system through practice.

How long it is kept

Audio and transcripts are retained for a configurable period, then deleted. Customers can set a shorter retention window or request deletion.

Model training

Customer content and learner voice data are not used to train third-party foundation models. We only use government approved models.

CERTIFICATIONS AND STATUS

Where we are, stated honestly

We publish status rather than badges we have not earned. Current position and target dates below.

FRAMEWORK

STATUS

SOC 2 Type II

Compliant.

ISO 27001

Compliant

GDPR/ India DPDP Act

Geography-specific Data Protection Laws followed

Penetration testing

Regular Cadence

FOR YOUR SECURITY REVIEW

Happy to answer any further questions

Security questionnaire responses, DPA, architecture overview and penetration test summary are available under NDA.