Security, Privacy & Compliance
How Metal Labs secures data, what we deliberately never handle, and how calling activity stays inside the rules. Written for compliance and security reviewers.
Last updated
What Metal Labs Is
Metal Labs places and receives phone calls for a lender or brokerage using an AI voice agent, and writes the outcome of each call back into that client's own CRM.
Your CRM stays the system of record. We do not replace it and we do not retain your contact database. We hold what is needed to place a call and report on it, for as long as your retention window allows.
For consumer information processed on your behalf, you are the controller and Metal Labs is the processor. We act on your documented instructions, and we do not sell or share consumer personal information.
How Data Is Secured
- In transit
- TLS on every external connection, with certificates renewed automatically. Internal service traffic does not cross the public internet.
- At rest
- PostgreSQL on Supabase and object storage on Google Cloud, both encrypted at rest. Recording buckets are private with no public objects.
- Your credentials
- CRM keys and telephony tokens are envelope-encrypted with Fernet, using a key held outside the database. The platform refuses to start without a valid key, so at-rest encryption cannot silently degrade.
- Access control
- JWT authentication, server-side role-based access control, and row-level tenant isolation. One client cannot reach another client's calls, recordings or leads.
- Audit trail
- Every change-making request is logged with actor, action, target, result and source IP.
- Outbound protection
- Client-configured webhooks resolve DNS and reject private and internal address ranges at request time, with redirects disabled.
What We Never Handle
Some of this is policy. Most of it is a design constraint: the platform has no field to put the data in.
- No Social Security numbers, dates of birth, or financial account numbers. The agent does not ask for them and no field stores them.
- No card or bank details. We take no consumer payments, so consumer data is outside PCI scope.
- No credit-report data. We are not a consumer reporting agency and do not pull, store or resell credit data.
- No protected health information. The platform is not designed for it and should not be used for it.
A hard deny-list stops sensitive CRM fields from ever being spoken aloud or reaching the language model, even when your CRM sends them to us. It covers loan amounts, property values, purchase prices, credit ratings, lead sources, consent tokens and internal record identifiers.
An optional guardrail prevents the agent from stating any rate, payment or APR at all, and instructs it to defer to your licensed staff. The agent does not underwrite, approve, deny, price or advise.
Retention and Deletion
- 90 days
- Call transcripts, AI summaries and audio recordings are deleted 90 days after the call. A scheduled sweeper removes the recording object from storage, not just the reference to it.
- Recordings are never public
- Playback uses a short-lived signed link, generated on request and valid for one hour by default. There is no permanent URL, and an expired link grants no access.
- On termination
- On written request, we delete your tenant data — calls, transcripts, recordings, agent configuration and stored credentials — within 30 days, and confirm in writing.
- Consumer requests
- We support export and erasure for an individual consumer record, actioned through you as the controller.
Call metadata — time, duration and outcome — is kept after the purge for billing and reporting integrity. It contains no conversation content.
Calling Compliance
Calling rules are enforced in code before a call is placed, not left to configuration or good intentions.
- Calling windows
- Every outbound call is checked against the federal 8:00–21:00 window in the called party's own local time, derived from their number and state.
- The baseline cannot be relaxed
- A client configuration cannot widen the federal window. Turning a workflow's own settings off falls back to the federal default, never to no restriction.
- It fails closed
- If we cannot determine the contact's timezone, the call is allowed only when it is inside the legal window in both Eastern and Pacific time — the full span of the continental United States. Unknown never means permitted.
- Do-not-call handling
- Contacts on your do-not-call and suppression lists are excluded, and we honour the stop-list stage in your CRM immediately before dialling. That check also fails closed: if your CRM cannot be reached, the call is held rather than placed.
- State licensing
- Calling can be restricted to the states where you are licensed.
- Pacing
- Per-account and per-campaign concurrency caps, configurable operating hours, and an optional weekend hold.
AI and Your Data
- We do not train, fine-tune or improve any AI model on your data or your consumers' conversations.
- Our speech, language and voice providers are contracted on terms that exclude customer content from their training.
- We do not pool data across clients. There is no shared lead pool and no cross-client analytics.
- We do not sell, rent or broker consumer data. There is no advertising component to this platform.
Infrastructure and Subprocessors
Metal Labs runs on Google Cloud Platform and Supabase, both independently certified to SOC 2 Type II. These providers process data on our behalf:
- Google Cloud Platform
- Compute and encrypted object storage for recordings.
- Supabase
- Managed PostgreSQL and authentication.
- LiveKit
- Real-time audio transport during a call.
- Twilio / Telnyx
- Telephony carriage.
- Deepgram
- Speech-to-text.
- OpenAI
- Language understanding.
- ElevenLabs
- Text-to-speech.
- Microsoft Azure (Speech)
- Text-to-speech, for agents configured with an Azure voice.
- Resend / Google Workspace
- Notification email to your staff.
Clients are notified of material changes to this list. A current copy is available on request.
Incident Response
Suspected incidents are triaged immediately. If a breach affects your data, we notify you without undue delay and within 72 hours of confirming it, with what is known, what is affected and what is being done. Audit and infrastructure logs support forensic reconstruction.
Reviewing Metal Labs? We answer security questionnaires.
Ask us for the current subprocessor list, architecture detail, or a completed questionnaire in your own format.
compliance@metallabs.io