Compliance

DPDP, encryption & ZDR

Digital Personal Data Protection Act controls, TLS 1.3 / AES-256, tenant isolation, Zero Data Retention.

DPDP

Voice audio and transcripts are personal data. Processing is purpose-limited to the contracted workflow. Data principals can request access and erasure via POST /v1/privacy/export and POST /v1/privacy/erase (admin JWT, tenant-scoped). Identify the subject with e164 or SHA-256 subject hash. Cross-border transfer is off by default for Indian tenants.

Export package

Export returns matching calls, transcripts, DLT consents, outbound messages, conversations, and the consent log including dnd_hit, dnd_clear, disclosure_played, trai_blocked, dlt_consent, and opt_out. Erasure anonymizes phones and transcript text to [erased] and writes an immutable privacy.erase audit event. TRAI/billing metadata may remain without the phone number.

Retention

SHRIS_RETENTION_DAYS defaults to 90 (BRD range 90–180). expireStaleRecords() drops transcripts and conversation turns older than the window. POST /v1/privacy/expire (admin) runs the same job. ZDR still shreds recordings after CRM sync when DPDP_ZDR_DEFAULT is true; this retention job is the time-based control for leftover transcripts.

Encryption

SRTP/TLS 1.3 in transit. AES-256 at rest with customer-managed keys on Enterprise VPC. Role-based access and immutable audit logs on every tool invocation.

Zero Data Retention

ZDR mode shreds recordings and transcripts immediately after CRM sync completes. Metadata required for billing and TRAI logs is retained per policy. SHRIS_HIPAA_MODE adds PHI-redacted logs and hipaa.guard audit events for healthcare tenants; conversation text remains AES-256-GCM at rest.

Need a live architecture session?

Book a demo or open the operations console to inspect campaigns, TRAI gates, and CRM actions.

Open Console