Enterprise-grade data security and privacy
Your customer data is protected at every touchpoint. Goldfish meets the strictest international security and privacy standards.
Six pillars of enterprise security
Built for CIOs, CISOs and procurement teams who treat security as a baseline, not a feature.
End-to-end encryption
Full data encryption both in-transit (TLS 1.3) and at-rest (AES-256). Keys managed via dedicated KMS.
SOC 2 & GDPR compliance
Built in full alignment with SOC 2 Type II, GDPR, and local privacy laws. Independent audits available under NDA.
Zero data retention
Optional Zero Data Retention mode for sensitive content — call data is purged immediately at session end.
Role-based access control
Granular permissions, SSO/SAML, and full audit logs across every action in the platform.
Regional data residency
Choose your data region (EU, US, IL). Data never leaves the chosen region without explicit consent.
Continuous monitoring
24/7 security monitoring, automated threat detection, and a documented incident response plan.
Data protection
- AES-256 encryption at rest, TLS 1.3 in transit
- Customer-managed encryption keys (BYOK) on enterprise tier
- Configurable retention windows (24h to 0s)
- PII masking and redaction available at ingest
Operational security
- Annual third-party penetration testing
- SOC 2 Type II audited controls
- GDPR Article 28 Data Processing Agreement available
- Vendor security review pack on request
Need our full security documentation?
We share SOC 2 reports, DPA, and architecture diagrams under NDA with qualified enterprise teams.