Trust Center

Security Brief

Last updated 31 July 2026

The short version: we never store your transcripts. STUDIO scores call transcripts. We process each transcript in memory for a single run and do not store the full transcript anywhere. We keep only the derived analysis needed to show and re-display your results.

Data flow

Your transcript (uploaded, or pushed from your notetaker)
   -> processed in memory by our Cloudflare Worker
   -> sent to a third-party AI model provider for scoring
   -> scores + evidence assembled, validated, returned to you
   -> (optional) report emailed to your chosen recipients

What we store vs. don't store

DataStored?Where / how long
Full call transcriptNoProcessed in memory only
Derived analysis (scores, confidence, short evidence excerpts, summaries, recommendations)YesCloudflare, keyed to a one-way SHA-256 hash of the transcript; retained indefinitely (no auto-expiry), deleted on request or account closure
Saved reports (Report History / auto-save, off by default)YesCloudflare storage; the full derived report incl. customer/company names and short excerpts; kept until you delete it or close the account
Rep performance trends (scores only, per rep)Yes, if trends are onCloudflare; no transcript or excerpts; up to 24 months
Scorecard templates you createYesCloudflare, under your account
Usage countersYes (against a hashed email)Cloudflare, rolling short windows
Application logsYesNo transcript content or model output; limited operational retention

Hosting and sub-processors

We build on SOC 2-compliant providers and inherit their infrastructure controls. Our own formal SOC 2 program is planned as we move toward general availability.

Access control

Encryption

Application security controls

Deletion requests

Full transcripts are never stored. The derived-analysis cache holds only scores plus short excerpts, keyed to a one-way hash; saved reports (Report History, off by default) and the scores-only rep-trend history are the other call-derived stores. All of it, along with templates and account data, is deleted on request or account closure. See our Data Handling Overview and Privacy Notice.

Questions

We're happy to complete security questionnaires and share our sub-processors' compliance reports on request: support@studio-moneyball.io.