Audio in
PilotCall captures the rep's microphone and the remote side of the call locally on the rep's Windows machine. The two streams stay separate and speaker-labeled.
Security & data handling
The architecture is deliberately simple to review: local capture, streamed transcription, server-side keys, and retention settings your team controls.
Data flow
PilotCall captures the rep's microphone and the remote side of the call locally on the rep's Windows machine. The two streams stay separate and speaker-labeled.
Audio is streamed to an enterprise speech-to-text service for real-time transcription over an encrypted connection. Temporary transcription tokens are issued per session; no long-lived transcription keys exist on the rep's machine.
Transcript context and the active playbook excerpts are sent to a leading large-language-model provider through PilotCall's authenticated server-side functions to generate the rep-facing suggestion.
Session logs are written locally under configurable retention settings your team controls. Playbooks are your uploaded documents; retrieval against them runs locally.
Security posture
Transcription and AI provider keys live server-side. The desktop app authenticates the rep and requests short-lived access per session.
Sign-in tokens are stored in the operating system's credential vault, not in config files or plaintext.
Subscriptions, usage, and session records are scoped per organization with row-level security. Users can only read their own organization's data.
The rep-facing overlay uses Windows display affinity so it can be excluded from screen sharing and recording. Validate this in your own conferencing setup during the pilot.
Transcript and session logging on the rep's machine is configurable, including turning it off. Retention expectations are agreed before live customer calls.
Every pilot starts on sample data. Consent wording, disclosure requirements for your jurisdiction, and who can see transcripts are reviewed before any real customer call touches the system.
Honest boundaries
PilotCall is pilot-stage software and does not yet hold SOC 2 or ISO certifications. Enterprise pilots include a security review against your requirements.
Call-recording and consent laws vary by state and country. Your team owns compliance for its calls; PilotCall's role is making the consent and retention settings explicit before launch.
Third-party processors: an enterprise speech-to-text service and a leading LLM provider, accessed through PilotCall's server-side functions. The named subprocessor list is shared with buyers during a pilot's security review.