Security & privacy
Built for calls that carry private things.
Wrenna answers for clinics, firms and shops where a single call can hold a diagnosis, a legal matter or a card number. So isolation and least privilege are not features we added — they are the shape of the system. Here is exactly how it works.
One business can never see another’s data
Every row that belongs to a business carries its identity, and the database itself refuses a read or a write that crosses the line — not application code that could be bypassed, but row-level security the query runs under. Isolation is the default, not a filter someone remembered to add.
Caller content stays inside your business
Transcripts, recordings and anything a caller said live only in your tenant. Our own operational plane — billing, health, the console our staff use — holds no caller or vendor content at all, by design. Staff reach a business’s data only under an explicit, time-boxed, audited grant.
Recordings are locked, and served one link at a time
Call audio is stored encrypted and is never a public URL. A recording is played only after the same access check the rest of the app runs, through a signed link that expires — so a leaked address is a dead address minutes later.
Every sensitive action leaves a trail
Who did what, to which record, and when — written as the change happens, not reconstructed afterward. Sign-in, exports and staff access to a business are all attributable.
Multi-factor authentication for regulated work
A business handling health information can require a second factor for every member, and the requirement is enforced at the door for the whole team — not a setting an individual can quietly turn off.
Data you can take with you, and delete
Your calls and their outcomes are yours to export. When you leave, your content leaves with you — retention windows are set per record class, not kept indefinitely by default.
What we are still working toward
We hold ourselves to the handling described above today. Formal third-party attestation (SOC 2) and a signed business-associate agreement for covered entities are on the roadmap; our current data-processing terms are published and versioned. If your procurement team needs specifics, our data-processing terms and privacy notice are the place to start, and a walkthrough call is the fastest way to get the rest.