Security

Enterprise security by default — and on-premise when default isn't enough

EU hosting, supports GDPR compliance, SSO and audit logs are standard. When your data can't leave your infrastructure, InOro runs fully on-premise.

InOro processes and stores customer voice data in the EU by default. For teams whose regulatory or contractual position requires it, a full on-premise deployment keeps every byte of audio, transcript and result inside your own infrastructure. SSO/SAML 2.0, role-based access, complete audit logs and anonymization of sensitive data are included in every deployment.

The full posture

🛡️

EU hosting, supports GDPR compliance

Data stored and processed exclusively in EU data centers by default.

🛡️

Full on-premise option

Audio, transcripts and results never leave your infrastructure.

🛡️

SSO, SAML 2.0, RBAC

Enterprise identity and access controls, per team, campaign or workspace.

🛡️

Full audit logs

Every access and query logged; every flag traceable to a call and moment.

🛡️

Sensitive-data anonymization

National IDs, card numbers, PII masked automatically in transcripts.

🛡️

No training on your data

Your recordings are never used to train models without written consent.

🛡️

Encryption in transit & at rest

TLS 1.2+ in transit, AES-256 at rest.

🛡️

DPA available on request

Data processing agreements ready for review, in EU and BPO chains.

Data residency

All customer voice data — recordings, transcripts, analysis results — is stored and processed in EU data centers by default. No transfer to third countries unless explicitly configured and contracted.

On-premise deployment

For teams that require it (regulated finance, defense, sensitive public sector), a full on-premise deployment installs InOro's stack in your own datacenter. Audio, transcripts and results never touch our infrastructure. Same features, same UX, deployed and updated per your change process.

Access controls

  • Single sign-on via SAML 2.0; OpenID Connect on request.
  • Role-based access per team, campaign, agent group.
  • Fine-grained permissions — who can listen, who can score, who can export.
  • Audit trail of every access, query and export.

Anonymization

Sensitive data — national IDs, card numbers, sector-specific PII — is masked automatically in transcripts and analytics views. Original audio is preserved with retention rules you define.

Model governance

Your recordings and transcripts are never used to train or fine-tune models without written consent. Any model updates that would benefit from your data require an opt-in DPA amendment.

Certifications and audits

InOro operates under ISO 27001-aligned practices. Formal certifications on our roadmap — request the current status under NDA.

Vendor DPA

Data processing agreements are available on request as processor. For BPO deployments, sub-processor arrangements per end client are supported.

Security FAQ

Is InOro SOC 2 or ISO 27001 certified?
InOro operates under ISO 27001-aligned practices. Formal certifications are on the roadmap; contact us for the current status under NDA.
Can we require our data to stay in Poland (or another specific EU country)?
Yes — EU data residency is the default; specific country-of-processing requirements can be accommodated. For strict data-locality, on-premise is the certain path.
How does InOro handle a data subject access request?
InOro provides tooling to locate all calls and derived data linked to an identifier; per-call export and deletion are supported via the app and API.
What is your incident response SLA?
Standard SaaS: 24h initial acknowledgment for critical incidents, 72h notification for data-breach events per GDPR. Custom SLAs available in enterprise contracts.
Do you sub-process to any third parties?
A short list of infrastructure and STT sub-processors is disclosed in the DPA. All are EU-based or contractually EU-hosted for InOro workloads.

Talk to security & procurement

30-minute call with an engineer on your security posture and requirements.