Security & Data Protection

How We Protect Your Clients' Data

Your callers trust your firm with sensitive information. We treat that trust as a non-negotiable obligation. Here is exactly how caller data is captured, transmitted, and protected at every step.

SOC 2 Type II
Vendor-certified
ISO 27001
Information security
HIPAA-eligible
Healthcare-grade
AES-256
Encryption

How a Call Flows Through Our System

Six steps, every one of them encrypted, every vendor independently certified.

1

Caller Dials Your Firm

Inbound call hits a U.S. carrier number provisioned through Twilio. Voice traffic is encrypted in transit via industry-standard TLS/SRTP.

Twilio: SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR
2

Sarah Answers (AI Receptionist)

Synthflow's AI agent handles the conversation on owned U.S. telephony infrastructure. Sarah is explicitly designed to capture only routing information — never medical details, diagnoses, medications, or PHI.

Synthflow: SOC 2, HIPAA, PCI DSS Level 1, ISO 27001, GDPR
3

Verbal Consent Captured

Before any text message is sent, Sarah asks an explicit SMS opt-in question. The caller's verbal response is recorded, timestamped, and logged. No SMS is ever sent without recorded affirmative consent — full TCPA compliance.

TCPA-compliant verbal opt-in with audit trail
4

Encrypted Workflow Processing

Call data flows over TLS-encrypted webhooks into n8n Cloud, an automation platform with AES-256 encryption at rest using a FIPS-140-2 compliant implementation. The compliance filter blocks any call without explicit consent from triggering downstream actions.

n8n Cloud: SOC 2 Type II, GDPR (DPA available)
5

Lead Delivered to Your Firm

Caller information is delivered to your firm's Gmail inbox and a private Google Sheet log under your control. Data lives inside Google Workspace, which holds the strongest possible compliance posture.

Google Workspace: SOC 2, ISO 27001, 27017, 27018, HIPAA-eligible with BAA
6

Optional SMS Confirmation to Lead

If — and only if — the caller verbally opted in, a confirmation text is sent via Twilio's A2P 10DLC carrier-approved channel. STOP automatically opts the recipient out of all future messages.

Twilio A2P 10DLC: carrier-vetted, consent-logged

Our Vendor Compliance Stack

Every platform in our data chain is independently audited and certified.

PlatformRoleCertifications
TwilioVoice + SMS carrierSOC 2, ISO 27001, ISO 27017, ISO 27018, HIPAA, PCI DSS, GDPR, CCPA, NIST
SynthflowAI voice agentSOC 2, HIPAA, PCI DSS Level 1, ISO 27001, GDPR
n8n CloudWorkflow automationSOC 2 Type II, GDPR (DPA), AES-256 encryption at rest
Google WorkspaceEmail + data deliverySOC 2, ISO 27001, ISO 27017, ISO 27018, HIPAA-eligible (with BAA)

Our Commitments to Your Firm

What we will and will not do with caller data, in writing.

No Third-Party Sharing

Caller information is never sold, rented, or shared with marketing partners, lead brokers, or any third party for promotional purposes. Ever.

No AI Training on Your Data

Caller conversations and case details are never used to train AI models — ours, our vendors', or anyone else's.

Minimal Data Capture by Design

Sarah is explicitly programmed to never capture medical details, diagnoses, medications, SSNs, insurance numbers, or other sensitive identifiers. The attorney handles all of that directly.

Verbal Consent for Every SMS

No text message is sent without recorded, timestamped, affirmative verbal consent from the caller. Full TCPA-compliant audit trail.

Encryption Everywhere

AES-256 encryption at rest. TLS encryption in transit between every system. No exceptions.

DPA Available on Request

A Data Processing Agreement is available for any firm that requests one, before client data flows through the system.

Regulatory Compliance Posture

How we map to the regulations that matter for personal injury intake.

TCPATelephone Consumer Protection ActCompliant

Verbal opt-in captured and logged before every SMS. STOP keyword auto-honored. Full consent audit trail per caller. A2P 10DLC carrier-registered messaging campaign.

HIPAAHealth Insurance Portability and Accountability ActMinimized exposure by design

Sarah is designed to never capture PHI (medical details, diagnoses, medications). Our system reduces your firm's HIPAA surface area rather than expanding it. Twilio and Google Workspace are HIPAA-eligible with BAAs available for firms that require them.

State Privacy LawsCCPA, CPRA, and similar state lawsCompliant

No sale or sharing of personal information. Right-to-delete supported. Privacy practices documented in our published Privacy Policy.

GDPRGeneral Data Protection Regulation (EU)Scope-dependent

GDPR governs EU residents' data. For firms representing U.S.-based clients, GDPR generally does not apply. For firms with EU client exposure, we can discuss specific requirements.

SOC 2 Type IIVendor certificationsInherited from underlying platforms

All four vendors in our data chain (Twilio, Synthflow, n8n, Google Workspace) hold SOC 2 Type II certifications independently audited by third parties. QuickReply AI will pursue its own SOC 2 Type II certification as we scale.

Need a Data Processing Agreement?

We provide a signed Data Processing Agreement to any firm that requires one before client data flows through the system. Reach out and we will send the template the same day.

Request a DPA

See also: Privacy Policy | Terms of Service

QUICKREPLY AI LLC | Wyoming, USA | Last updated: May 2026

This page describes our security architecture as of the date above. Compliance certifications listed reflect the published posture of our underlying vendors and are subject to change. We update this page when material changes occur.