Security
Your conversations
stay yours.
Bylda listens to the most sensitive thing your company owns: what customers actually say. We built the security posture that responsibility demands, and we publish it plainly.
SOC 2 Type II
Independently audited controls across security, availability, and confidentiality. Report available under NDA.
Encrypted end to end
AES-256 at rest, TLS 1.3 in transit. Keys managed in an HSM-backed service with routine rotation.
SSO & SCIM
SAML 2.0 and OIDC with your identity provider. Automated provisioning and instant deprovisioning.
Data residency
Choose US, EU, or UK processing. Data stays in region — including transcripts, embeddings, and backups.
Full audit trail
Every read, every write, every export — attributed to an actor and a timestamp, exportable to your SIEM.
No training on your data
Your conversations are never used to train shared or third-party models. Contractually, not just as policy.
The line we don't cross
Isolation is the default.
Every customer's data lives in a logically isolated tenant with its own encryption context. Models read your data to serve you, in your session, and nothing crosses that boundary.
- No shared embeddings between tenants
- No human review of your transcripts without written, per-incident consent
- Subprocessors published, with 30 days' notice before any change
- Deletion honored within 30 days, backups included
Questions we get asked
Answered plainly.
No. Bylda enforces consent rules per region and per meeting type, using the same disclosure your conferencing tool provides. In two-party consent jurisdictions, recording does not begin until consent is captured. Admins configure this once, and it applies to every rep automatically.
Access mirrors the permissions of your CRM. If a rep cannot see an opportunity in Salesforce, they cannot see its conversations in Bylda. Managers see their own team. Admins configure exceptions explicitly, and every access event is logged.
You export everything — transcripts, summaries, extracted fields, and the audit log — in open formats. We then delete your tenant within 30 days, including backups, and send written confirmation when it is done.
Our current subprocessor list is published and versioned, and enterprise customers are notified 30 days before any addition. All providers operate under zero-retention agreements: they process a request and retain nothing afterward.
Yes, on the Enterprise plan. We support a private deployment inside your AWS or Azure account, with your keys and your network boundary. Talk to us about timelines — it typically takes two weeks.
Cleared by your security team.
We answer questionnaires in days, not weeks. Join the waitlist and note the review — the SOC 2 report and DPA arrive before your invite.