A sovereign platform,
your choice of models
Our orchestrator, dashboard, and API run entirely on EU infrastructure — no US or non-EU cloud providers. The AI models you plug into it are your call. We help you pick the most compliant stack for your use case.
The platform layer, fully European
Everything we build runs on EU-based providers. No AWS or GCP US regions in the path. No transatlantic detour for orchestration, storage, or control-plane traffic.
Orchestrator on EU compute
Voice orchestration, session state, and call routing run on EU-resident infrastructure end-to-end.
Recordings & transcripts in EU
All persistent data — call recordings, transcripts, analytics — stored in EU regions only.
Dashboard & API in EU
The management plane, dashboard, and public API are served from EU regions. No cross-border telemetry.
Secrets in an EU vault
Customer keys and credentials live in a vault hosted in the EU, isolated per tenant.
The model layer is your decision
We integrate with the best providers in the world — many of them American. That's a trade-off you control. Pick whatever fits your latency, language, and compliance needs. We won't hide where the request is going.
US-based providers
OpenAI, Deepgram, and other industry-standard providers. Best quality on many languages today. Crossing the Atlantic per call is the trade-off.
OpenAI · Deepgram · InworldEU-resident providers
Mistral, Gladia, ElevenLabs (UK / GDPR-aligned), or Gemini via Vertex AI on EU-West4 (Netherlands). Data stays in Europe.
Mistral · Gladia · Gemini EU-West4 · ElevenLabs UKSelf-hosted models
For zero external dependencies: Piper (TTS) and other open-source models hosted alongside our orchestrator or inside your private cloud.
Piper · self-hosted Whisper · custom modelsNeed everything in Europe? Here's how
These combinations keep every byte of data inside the EU (or UK with GDPR equivalence). We advise you on the best fit for your language and use case.
French / Western Europe
Dutch / multilingual
Regulated / on-premise
Combinations evolve quickly. Talk to us about what's currently best for your use case.
Security by default
Defaults that match what enterprise security teams want to see in their first review.
AES-256 encryption at rest
All persistent storage encrypted with industry-standard symmetric encryption.
TLS 1.3 in transit
Modern TLS for every API call, every webhook, every internal RPC.
HMAC-signed webhooks
Every webhook is signed so you can verify the request came from us — not a spoofer.
Tenant isolation
Per-organization data partitioning. Strict access controls and audit logging on every read.
Vault-managed secrets
Every credential lives in a dedicated secret store, never in environment dumps or logs.
BYOK for everything
Use your own API keys with model providers. We never see them; you pay providers directly.
Want help picking the right stack?
Tell us your use case and we'll map the most compliant provider combination. Security and DPA documents available on request.