Security & data handling

Know exactly where call data goes before a rep ever uses it.

The architecture is deliberately simple to review: local capture, streamed transcription, server-side keys, and retention settings your team controls.

PrivateRep-only overlay view
Playbook matchObjection pattern detected
RetentionConfigurable local log files
PrivateRep-only overlay view
Playbook matchService inquiry detected
CRM integrationPlanned API integration
PrivateRep-only overlay view
Playbook matchObjection path detected
SEO integrationPlanned API integration

Data flow

Four steps, no mystery middle.

01

Audio in

PilotCall captures the rep's microphone and the remote side of the call locally on the rep's Windows machine. The two streams stay separate and speaker-labeled.

02

Transcription

Audio is streamed to an enterprise speech-to-text service for real-time transcription over an encrypted connection. Temporary transcription tokens are issued per session; no long-lived transcription keys exist on the rep's machine.

03

Guidance

Transcript context and the active playbook excerpts are sent to a leading large-language-model provider through PilotCall's authenticated server-side functions to generate the rep-facing suggestion.

04

Retention

Session logs are written locally under configurable retention settings your team controls. Playbooks are your uploaded documents; retrieval against them runs locally.

Security posture

What is actually in place today.

No API keys on the laptop

Transcription and AI provider keys live server-side. The desktop app authenticates the rep and requests short-lived access per session.

Credentials in Windows Credential Manager

Sign-in tokens are stored in the operating system's credential vault, not in config files or plaintext.

Organization isolation

Subscriptions, usage, and session records are scoped per organization with row-level security. Users can only read their own organization's data.

Private overlay

The rep-facing overlay uses Windows display affinity so it can be excluded from screen sharing and recording. Validate this in your own conferencing setup during the pilot.

Configurable local logging

Transcript and session logging on the rep's machine is configurable, including turning it off. Retention expectations are agreed before live customer calls.

Consent before live use

Every pilot starts on sample data. Consent wording, disclosure requirements for your jurisdiction, and who can see transcripts are reviewed before any real customer call touches the system.

Honest boundaries

What we will not claim.

PilotCall is pilot-stage software and does not yet hold SOC 2 or ISO certifications. Enterprise pilots include a security review against your requirements.

Call-recording and consent laws vary by state and country. Your team owns compliance for its calls; PilotCall's role is making the consent and retention settings explicit before launch.

Third-party processors: an enterprise speech-to-text service and a leading LLM provider, accessed through PilotCall's server-side functions. The named subprocessor list is shared with buyers during a pilot's security review.