Data handling
MetisPro processes voice calls in real time and stores call transcripts, metadata, and outcomes for the customers who deploy it. Every deployment has a written data-handling agreement scoped to the customer's needs.
What we capture
Call audio (during processing only), transcripts, caller phone number, call outcome, and any structured data written back to your systems (bookings, escalations, contacts).
How long we keep it
Transcripts and call metadata are retained per your contract — typically 12 months, adjustable for regulated verticals. Raw audio is not retained by default.
Who has access
Access is limited to the Metis Khemis team members supporting your account and any authorized users on your team. Audit logs are available on request.
Security posture
MetisPro runs on modern, security-hardened infrastructure. Our baseline posture includes:
- TLS 1.2+ everywhere — no unencrypted traffic in or out of the platform.
- Encrypted at rest — all transcripts and structured data encrypted in storage.
- Role-based access control — least-privilege access for all team members and support staff.
- Supabase RLS — row-level security policies on all customer data tables.
- Stripe compliance passthrough — we do not store payment card data; all payment handling flows through Stripe's PCI-DSS environment.
- Vercel + Cloudflare edge — enterprise DDoS protection, WAF, and edge security.
- SOC 2 alignment — control framework aligned with SOC 2 Type II; formal audit path available for enterprise deployments.
- HIPAA-ready posture — available for medical, dental, and health-adjacent deployments with a signed BAA.
Privacy
Our privacy policy governs how we collect, use, store, and share personal information. We do not sell customer data, we do not use customer voice data to train third-party models without explicit permission, and we do not share transcripts with any party outside your deployment scope.
Read the full privacy policy or contact us for a data-processing agreement (DPA).
Accessibility
Metis Khemis's public-facing website targets WCAG 2.2 AA. Voice AI itself expands accessibility for many users (immediate answer, multi-language, no phone-tree labyrinth) but is not a replacement for TTY / TDD, ASL video relay, or other accommodations required by regulation. Deployments that must meet Section 508 or ADA-Title II requirements are handled through the enterprise track.
Government & regulated deployments
Deployments for government, defense, healthcare, and other regulated sectors run through our enterprise engagement track. This includes:
- Data-residency options (US-only processing available)
- Private-infrastructure deployment paths
- CMMC-aligned posture for defense contractors
- HIPAA BAA execution for medical deployments
- Full audit-log delivery on request
- Custom escalation and human-review workflows
Reporting a security issue
If you believe you've found a security vulnerability in MetisPro or our infrastructure, please email security@promx.ai. We respond to all legitimate security reports and treat responsible disclosure with the seriousness it deserves.
Uptime
MetisPro's target availability is 99.9%. Enterprise deployments include contractual SLAs. A public status page is on the roadmap; enterprise customers get status alerts on the mechanisms we support (email, Slack, webhook).
Questions we didn't answer here?
Legal, compliance, or security reviews — reach out and we'll get you what you need.