Trust

Security, privacy and data handling

Last reviewed: . Written so your IT or legal team can answer most of a questionnaire without emailing us. Anything they still need, ask at hello@yappa.com.au.

Where your data lives

Your account data, leads, call records and transcripts sit in Sydney, Australia: the application runs on Fly.io in Sydney and the database is Neon in Sydney. Call recordings are stored in Cloudflare R2 in the Asia Pacific region.

Two parts are not in Australia, and we would rather say so than let you discover it in an audit. The voice platform that carries the audio and turns speech into text, and the language model that decides what the AI says, both run in the United States. Audio and the words spoken on a call pass through those services while the call is happening. If in-country processing end to end is a hard requirement for you, tell us before you sign rather than after.

Encryption and access

Keeping accounts apart

Yappa is multi-tenant, and separation is enforced by the database itself. Every table carrying customer data has a row-level security policy that scopes reads and writes to the owning account, so a query that forgot to filter returns nothing rather than someone else's leads. Each account also gets its own telephony sub-account, which keeps numbers, caller reputation and billing separate.

Actions taken by the Yappa team inside an account are written to an internal audit log.

What happens before every call

Every outbound call passes one compliance gate before it is placed. There is no override flag, and the gate fails closed: if it cannot confirm something is allowed, the call does not happen.

Every decision, allowed or refused, is written to an append-only audit trail with the reason. Nobody, including us, can edit or delete it, and you can read and export it yourself from the Compliance tab in your dashboard.

Calls also carry disclosure by design. The recording notice is checked at dial time and a call will not be placed without it, and the AI never denies being an AI if a person asks.

Retention and erasure

Sub-processors

ProviderWhat forWhere
VapiVoice orchestration and speech to textUnited States
TwilioPhone numbers, calls and SMSAustralia and United States
AnthropicThe language model on the call, and call scoring where enabledUnited States
NeonApplication databaseSydney, Australia
Fly.ioApplication serversSydney, Australia
Cloudflare R2Call recording storageAsia Pacific
VercelDashboard and website hostingGlobal edge
ResendTransactional and notification emailUnited States
StripePayments and subscriptionsAustralia and United States
ClerkDashboard sign-inUnited States

What we do not have

Yappa is a small Australian company and does not hold ISO 27001, SOC 2, PCI DSS certification or IRAP assessment. Those are real, expensive programmes and claiming them loosely would be worse than not having them. If your procurement requires one, say so early: we will tell you honestly whether it is something we can commit to for your timeline rather than let it surface at contract stage.

What we do have is the list above, all of it verifiable in the product: the compliance audit trail you can export yourself, recordings you can play and delete, and an erasure that is a button rather than a support ticket.

Reporting a security problem

Email hello@yappa.com.au with the word SECURITY in the subject. Tell us what you found and how to reproduce it. We will confirm we have it, keep you posted while we fix it, and we will not pursue anyone who reports a genuine problem in good faith.

Privacy policy · Acceptable use · API documentation