Security

What we do with your calls, precisely.

Sales calls are among the most sensitive material a company has. This page says exactly what happens to them — including the parts we have not built yet.

Doing diligence? The questions your reviewer is about to ask — retention, subprocessors, export, deletion, cancellation, ownership, accuracy, and what we do not have — are answered on the due-diligence page, and how often we are wrong is measured and published on the accuracy page.

Where your data lives

Everything Talqo stores runs on EU infrastructure in Frankfurt, Germany — application, database and file storage. No production data leaves the EU except where a subprocessor is listed on our subprocessors page, with its transfer mechanism named.

Transcripts are not kept

A transcript is processed and discarded. We keep the structured output — the deal read, the scores, the receipts — not the conversation.

A transcript waiting in the queue is auto-purged after 30 days, whether or not it was ever processed.

Our AI subprocessor, Anthropic, processes transcripts under a DPA and EU Standard Contractual Clauses. Anthropic retains them for up to 30 days (longer only if flagged for trust and safety review) and never uses them for training.

How credentials are held

  • Customer passwords: PBKDF2-SHA512, 100,000 iterations, unique salt per user. We cannot read them.
  • CRM and AI credentials — your HubSpot token, your Azure key: AES-256-GCM encrypted at rest, decrypted only in memory at the moment of a call, never returned by any API.
  • Ingestion API keys: hashed (SHA-256). Shown once at creation and never again.
  • Webhook signing secrets: generated by us, never chosen by you, shown once, and rotated automatically whenever the endpoint changes.

Who can see what

Access is scoped by role, and enforced on the server — not by hiding buttons. A rep sees their own calls. A manager sees their direct reports. An admin sees their company. No role reaches another company's data, ever.

And nothing about a person is hidden from that person: every word a manager reads about a rep, the rep reads too. That is the mirror rule, and it is enforced in code and locked by tests.

What is written down

Every CRM write is audited: the field, the old value, the new value, who approved it, when, and the quote that justified it. Deletions are logged. Data-subject exports and erasures are logged.

Retention is set per company, and there is a dry run so you can see exactly what a purge would remove before it removes it.

Your rights, and how to use them

Export or erase any individual's data on request, from the admin panel, with the result logged. We support access, rectification, erasure, restriction and portability requests under GDPR. Contact hello@talqo.dk.

What we do not have

We would rather you learn this here than in a security review.

  • No ISO 27001 or SOC 2 certification. We are a young company and we have not been audited. When that changes this page changes.
  • No third-party penetration test yet.
  • No uptime SLA outside a signed agreement.
  • No bug bounty programme. If you find something, email hello@talqo.dk and we will answer the same day.

We are not going to describe a control we cannot show you. A security page that lists everything and admits nothing is a page written for procurement, not for you.

Reporting something

hello@talqo.dk. Tell us what you found and how to reproduce it. We will confirm receipt within one working day and tell you what we are doing about it.

Chad Kalik trading as Talqo · CVR 39829630 · København, Denmark
Platform and data hosted in the EU (Frankfurt) · hello@talqo.dk