SECURITY AND TRUST
UpTroop runs daily practice for frontline teams at enterprise scale, including voice conversations. This page sets out UpTrop's information security & data policy.
CORE CONTROLS
Data encrypted in transit with TLS 1.2 or higher, and at rest with AES-256.
Role-based access for administrators, managers and learners. Least-privilege internal access, reviewed periodically, with audit logging of administrative actions.
Hosting region is selected per deployment. US customer data can be hosted in a US region.
Learners join through a one-time passcode on their existing channel — no shared credentials and no personal email required. SSO/SCIM available for user & administrator accounts.
Each customer tenant is physically separated. Your content, scenarios and learner records are never used to train models for another customer.
Automated backups with defined recovery objectives, and monitored uptime.
VOICE AND CONVERSATION DATA
Voice raises the bar on privacy review, so we state this plainly rather than leaving it to the DPA.
Practice sessions between a learner and an AI partner. These are simulations, not recordings of real customers, so no customer PII enters the system through practice.
Audio and transcripts are retained for a configurable period, then deleted. Customers can set a shorter retention window or request deletion.
Customer content and learner voice data are not used to train third-party foundation models. We only use government approved models.
CERTIFICATIONS AND STATUS
We publish status rather than badges we have not earned. Current position and target dates below.
FRAMEWORK
STATUS
SOC 2 Type II
Compliant.
ISO 27001
Compliant
GDPR/ India DPDP Act
Geography-specific Data Protection Laws followed
Penetration testing
Regular Cadence
FOR YOUR SECURITY REVIEW
Security questionnaire responses, DPA, architecture overview and penetration test summary are available under NDA.