Skip to main content

Enterprise-grade data security and privacy

Your customer data is protected at every touchpoint. Goldfish meets the strictest international security and privacy standards.

SOC 2 Type IIGDPRISO 27001HIPAA Ready

Six pillars of enterprise security

Built for CIOs, CISOs and procurement teams who treat security as a baseline, not a feature.

End-to-end encryption

Full data encryption both in-transit (TLS 1.3) and at-rest (AES-256). Keys managed via dedicated KMS.

SOC 2 & GDPR compliance

Built in full alignment with SOC 2 Type II, GDPR, and local privacy laws. Independent audits available under NDA.

Zero data retention

Optional Zero Data Retention mode for sensitive content — call data is purged immediately at session end.

Role-based access control

Granular permissions, SSO/SAML, and full audit logs across every action in the platform.

Regional data residency

Choose your data region (EU, US, IL). Data never leaves the chosen region without explicit consent.

Continuous monitoring

24/7 security monitoring, automated threat detection, and a documented incident response plan.

Data protection

  • AES-256 encryption at rest, TLS 1.3 in transit
  • Customer-managed encryption keys (BYOK) on enterprise tier
  • Configurable retention windows (24h to 0s)
  • PII masking and redaction available at ingest

Operational security

  • Annual third-party penetration testing
  • SOC 2 Type II audited controls
  • GDPR Article 28 Data Processing Agreement available
  • Vendor security review pack on request

Need our full security documentation?

We share SOC 2 reports, DPA, and architecture diagrams under NDA with qualified enterprise teams.