Security

Security at Brook

Brook calls the numbers your customers call, so we treat that access with care. Here's how we protect your data, your agents, and your callers.

Encryption everywhere
All traffic runs over TLS 1.2+, and data is encrypted at rest with AES-256. Test-call metadata and transcripts are no exception.
Call data, handled carefully
We capture only what a check needs — verdicts, latency, and transcripts. Raw call audio is never retained without your explicit opt-in.
Least-privilege access
Internal access is scoped and logged. SSO, SAML, and audit logs are available on the Scale tier for your own team controls.
Isolated infrastructure
Brook runs on hardened cloud infrastructure with per-tenant isolation, automated patching, and infrastructure-as-code reviews.
Secrets & credentials
Provider keys and webhook secrets are stored in a managed secrets vault, encrypted, rotated, and never written to logs.
Monitoring the monitor
We watch our own checkers. Anomalies in dialing, latency, or error rates page our on-call team around the clock.
What we collect

Only what a health check needs

We don't ask for your customer database or your call recordings. To tell you whether an agent is working, Brook stores a deliberately small footprint:

  • The phone numbers you ask us to monitor
  • Test-call results: pass / fail verdicts, latency, and timestamps
  • Transcripts of what your agent said, to score greetings and answers
  • Alert routing details for email, Slack, Discord, and custom HTTP endpoints
  • You set retention windows, and you can export or delete your data at any time.
Compliance

Where we are, honestly

We'd rather tell you exactly where our compliance program stands than wave a badge.

Live
GDPR-aligned data handling
Data processing agreements, regional data handling, and deletion-on-request are available now for teams in the EU and UK.
Planned
Self-hosting
For air-gapped, offline, or compliance-bound teams, self-hosted health checks and Voice QA are on the roadmap so calls never leave your network.
Responsible disclosure

Found a vulnerability? We want to hear from you. Email a detailed report and we'll acknowledge within two business days and keep you posted through the fix. We don't pursue legal action against good-faith research.

ask@brookai.co