Security & Privacy

Security is the architecture,
not an afterthought.

Your clients trust you with the worst moments of their lives. We build Bespoke OS so that trust is structural — enforced in how the system works, not just promised in a policy. Here’s what’s built in today, and the formal assurances we’re pursuing ahead of our Q3 2026 launch.

Built in today

Multi-tenant isolation

Every database query is scoped to your firm's ID at the API layer — no shared views, no cross-firm reads. Isolation is enforced by automated tests that run against every resource type.

Encrypted credential vault

Your provider keys (email, phone, storage, AI) are encrypted at rest with Fernet symmetric encryption. Secrets are decrypted only in memory at the moment of use and never written to logs.

Signed webhooks

Inbound events are cryptographically verified before they touch your data: HMAC-SHA256 for voice-AI transcripts and email sync, Ed25519 for carrier SMS. Unsigned traffic is rejected.

Per-firm API keys

Your firm brings its own carrier, email and voice accounts. Keys are yours, numbers are yours, data is yours — Bespoke orchestrates, it doesn't own.

Transient AI processing

Calls to large language models are processed and discarded. Your case files, medical records and client communications are never used to train models.

Isolated object storage

Documents live in dedicated cloud object storage behind a signed-URL layer, with per-firm path scoping and no public buckets.

Scoped session tokens

Staff and client-portal sessions use separate JWT token types with distinct scopes — a portal token can never touch staff endpoints.

Human-in-the-loop AI

AI-extracted facts (medical visits, triage classifications) land as pending until a human confirms them. Nothing AI-generated becomes case-of-record silently.

Compliance roadmap

The assurances larger firms expect — in motion.

We’re building toward formal, third-party-verified security assurances ahead of general availability. If your firm or your clients require specific attestations, tell us — it shapes our priorities.

SOC 2 readiness

Working toward SOC 2 examination with continuous compliance monitoring, so our controls are independently verified — not just self-described.

Third-party penetration testing

Independent security testing planned before general availability, with findings remediated and summarized for customers.

Security questionnaires welcomed

We'll complete your firm's or your clients' security due-diligence questionnaires as part of early access.

Sensitive-records handling

Medical records flow through the platform, so we're evaluating the safeguards and agreements that class of data demands.

Statuses above describe work in progress and planned initiatives, not completed certifications.

Data ownership

Your matter. Your data. Full stop.

  • Firms can export their complete record set at any time — cases, documents, communications and chronologies.
  • Client-portal sharing is opt-in per item. Nothing is visible to a client unless a staff member shares it.
  • Deleting a lead or case removes its channels and messages with it.
  • We never sell, share, or aggregate firm data across tenants.

Questions from your IT reviewer?

We'll walk your team through the architecture directly.