Trust center
Security at Sales Lab.
Sales conversations are some of the most sensitive data in your organization. Every layer of Sales Lab is designed to be auditable, minimally trusted, and explicit about what we do — and do not — do with your team’s data.
Where your data lives
Application & database. Supabase Postgres in the us-east-1 region (AWS Virginia). Encrypted at rest with AES-256.
Voice infrastructure. ElevenLabs — speech-to-speech inference, US-East. Audio streams are never persisted on our side. ElevenLabs retains transcript snapshots only as required to deliver their API.
Scoring model. Anthropic Claude. US region. Inputs are processed for inference and not used to train Anthropic models.
Email. Resend (US region) for magic-link sign-in and scorecard summaries. Recipients are limited to your own users.
In transit. TLS 1.3 between every hop. HSTS preloaded.
Who can access it
Your company admins. Can read every scenario, scorecard, and transcript belonging to your tenant. Reps can read only their own.
Sales Lab engineers. Production database access is limited to a named on-call rotation, requires hardware-backed MFA, and is broken-glass only — every session is time-bound, justified in writing, and logged in a tamper-evident audit trail.
No third-party access. We do not sell, share, or rent your data to anyone. Subprocessors below are operationally required and contractually limited.
Audit logging
Every admin action — scenario create / edit / archive, KB edit, role change, share-token generation, and scorecard read — is logged with actor user-id, IP address, user-agent, and a timestamp. Logs are immutable for 365 days.
Compliance roadmap
Subprocessors
| Subprocessor | Purpose | Data | Region |
|---|---|---|---|
| Supabase | Application database, auth, file storage | All tenant records | us-east-1 |
| ElevenLabs | Real-time voice synthesis & speech-to-text | Live audio + transcripts | US-East |
| Anthropic | Scorecard generation (Claude) | Transcript text (inference only) | US |
| Resend | Transactional email | Email address, scorecard summary | US |
| Vercel | Application hosting & edge runtime | Request metadata | Global edge, US-primary |
Reporting a vulnerability
Email ben@tamras.co. We acknowledge within one business day, never threaten or pursue good-faith researchers, and credit reporters who request it on this page after the fix ships.
Data export & deletion
Export. Admins can request a JSON export of every scenario, KB doc, session, transcript, and scorecard at any time.
Deletion. A signed delete request from a verified admin removes all tenant data — including audio blobs and third-party derived state — within 30 days.
Last updated · 2026-04-22