Trust

Security

This page is maintained by AnswerFlow to answer common security and privacy questions about our platform. It describes current practices and is not a certification or independent audit report.

Last updated: July 2026

Encryption in transit

Traffic to answerflow.in and the platform is served over HTTPS/TLS.

Access controls

Platform access is authenticated, and internal access follows least privilege.

Managed hosting

We run on managed cloud infrastructure with provider-level physical and network security.

Shared responsibility

We secure the platform; customers manage their users, permissions and call consent obligations.

Data handling

  • Customer call transcripts and lead data are processed only to deliver the service the customer has configured.
  • We do not sell customer or caller data.
  • Data is retained for the life of the account and deleted on request after termination.

Subprocessors and integrations

AnswerFlow relies on third-party providers for hosting, telephony and AI model inference, plus any CRM or calendar integration a customer chooses to connect. Integrations are only enabled with the customer's explicit authorisation. A current subprocessor list is available on request.

Operational practices

  • Changes are reviewed before release to production.
  • Secrets and API keys are stored in managed secret storage, never in source code.
  • Security-relevant incidents are investigated and affected customers are notified.

Compliance

We follow the data protection expectations described in our Privacy Policy. If your procurement process requires specific certifications, questionnaires or a data processing agreement, contact us and we will respond with what we can currently provide.

Report a vulnerability

If you believe you have found a security issue, email info@answerflow.in with steps to reproduce. Please give us reasonable time to investigate before any public disclosure. We appreciate responsible reports.