Security & Trust

Your bookings and customer records live in Canada. Your call audio and its transcript pass through the United States.

Cedri is built for dental clinics, law firms, and anyone who handles information they can't afford to leak. Here is exactly how we store it, who can touch it, and the line we will never cross: we never train AI on your data.

Where your data lives

Your bookings, customer records, and call transcripts are stored in a Canadian data centre (ca-central-1). Live call audio, its recordings, and the transcript generated during the call are processed and stored by our voice infrastructure provider in the United States, which also handles speech recognition and voice synthesis; see our Privacy Policy for details.

Bookings and transcripts in Canada

Your business data, bookings, customer records, call transcripts, and account details are stored in Canada (ca-central-1). That is the copy Cedri holds and the one you work with every day.

What leaves the country

To answer a call at all, the audio has to reach our voice infrastructure provider in the United States. Live call audio, its recordings, and the transcript that provider generates are processed and stored there, so personal information is processed outside Canada during a call.

One owner: you

The data Cedri handles is your business's data. We hold it for one reason: to run your receptionist.

How it's encrypted

Calls and data are protected at every step, both moving across the network and sitting at rest. Every webhook between our partners is signature-verified, so we can prove an event really came from where it claims.

TLS 1.2+ in transit

Every call leg and API request is encrypted with TLS (1.2+), the current standard for data on the move.

AES-256 at rest

Transcripts, customer records, and account data are encrypted with AES-256 while stored in our Canadian data centre.

Signature-verified webhooks

Events between Cedri and its partners are signed and verified, so spoofed calls and data can't slip in.

Privacy law, handled

Cedri is aligned with PIPEDA and Quebec's Law 25, with privacy built into how calls, recordings, and customer data are handled. Our internal controls are SOC 2-aligned. We follow the practices, and we'll say "aligned," not "certified," because that's the honest word.

PIPEDA-aligned

Built to meet Canada's federal privacy standard for handling personal information.

Aligned with Law 25

Quebec's modern privacy rules are reflected in how we collect, store, and delete data.

SOC 2-aligned controls

Access, logging, and change controls follow SOC 2 practices. We say aligned, not certified.

Ready to stop missing calls? Set it up in about five minutes.

Get started

We never train AI on your data

This is the one most people ask about, so we'll be blunt. We never use your calls, recordings, transcripts, or customer information to train our AI models, and our providers are contractually barred from training on it. Your data runs your receptionist. That's the only thing it's for.

You stay in control

You decide how long recordings and transcripts are kept, and you can delete any of them from the dashboard whenever you want. If you ever leave, account deletion is supported with a 30-day window.

Set your retention

Choose how long recordings and transcripts are kept. You hold the dial, not us.

Delete any record, anytime

Remove any individual recording or transcript directly from your dashboard.

Account deletion, 30-day window

Close your account and your data is deleted within 30 days, except where the law requires us to keep it.

Need a closer look before you sign?

We're happy to walk your team or your privacy officer through any of this. Email support@cedri.ca for a security review, or set up your receptionist and be live today.

Prefer to call? Demo line: (437) 475-4321