Hi All We are building a Salesforce AppExchange e...
# general-english
e
Hi All We are building a Salesforce AppExchange enterprise app on top of Vapi.ai. During a product demo with a prospect, we were asked about the security of our data. Based on this, we have a few queries regarding how data is handled at Vapi.ai. - Since all conversation data passes through LLM, TTS, and STT layers, does these vendors store our data? If yes, how is the data secured? - What security measures does Vapi.ai implement to protect customer data and sensitive information such as credit card numbers, personal details (email addresses, phone numbers, bank account numbers), or any other confidential data shared during conversations? - Given that data can be fetched or pushed to external systems via tools triggered within conversations, how does Vapi.ai ensure the protection of sensitive data? - Does Vapi.ai implement data masking with dummy data before sending it to an LLM for processing? Any insights on the above questions would be greatly appreciated. While I have reviewed the documentation available on the Vapi.ai Trust Center, I could not find sufficient information addressing these specific concerns. - Additionally, can customers use Vapi.ai with a zero data retention policy concerning data stored with external vendors such as LLMs, transcribers, etc.? Looking forward to your response.