Trust
Security
This page is maintained by AnswerFlow to answer common security and privacy questions about our platform. It describes current practices and is not a certification or independent audit report.
Last updated: July 2026
Encryption in transit
Traffic to answerflow.in and the platform is served over HTTPS/TLS.
Access controls
Platform access is authenticated, and internal access follows least privilege.
Managed hosting
We run on managed cloud infrastructure with provider-level physical and network security.
Shared responsibility
We secure the platform; customers manage their users, permissions and call consent obligations.
Data handling
- Customer call transcripts and lead data are processed only to deliver the service the customer has configured.
- We do not sell customer or caller data.
- Data is retained for the life of the account and deleted on request after termination.
Subprocessors and integrations
AnswerFlow relies on third-party providers for hosting, telephony and AI model inference, plus any CRM or calendar integration a customer chooses to connect. Integrations are only enabled with the customer's explicit authorisation. A current subprocessor list is available on request.
Operational practices
- Changes are reviewed before release to production.
- Secrets and API keys are stored in managed secret storage, never in source code.
- Security-relevant incidents are investigated and affected customers are notified.
Compliance
We follow the data protection expectations described in our Privacy Policy. If your procurement process requires specific certifications, questionnaires or a data processing agreement, contact us and we will respond with what we can currently provide.
Report a vulnerability
If you believe you have found a security issue, email info@answerflow.in with steps to reproduce. Please give us reasonable time to investigate before any public disclosure. We appreciate responsible reports.