Trust & Security
Private by design.
Communication is sensitive. Making Yourself Clear (Myc) is built so your transcripts stay yours — with concrete, verifiable controls that satisfy security and legal teams.
The short version
No bot joins your calls — Making Yourself Clear works from transcripts you already have. Every transcript is stripped of personal information before any AI sees it, and you can view exactly what was sent. We don’t train on your data. And if your security team needs more, you can route analysis through your own AI provider or self-host the whole system so transcripts never leave your infrastructure.
How your transcript flows
Five steps, every analysis — and you can see what happens at each one.
- 1
Transcript
You upload text you already have. No bot, no recording.
- 2
Redaction
PII is stripped by Microsoft Presidio before anything leaves the system.
- 3
Analysis
Only the redacted text is analyzed — and OpenAI doesn’t train on it.
- 4
Report
You get coaching — plus a view of exactly what was sent.
- 5
Retention
We don’t train on or sell your data. Zero data retention is available for enterprise-scale deployments; self-host keeps everything in your perimeter.
What we do
PII redaction before any AI call
Before any transcript is sent to an LLM, Microsoft Presidio plus custom recognizers reduce every person’s name — yours and the other speakers’ included — to bare initials, and replace contact info, government IDs, card numbers, employee IDs, and credentials with opaque tokens.
See exactly what was sent
Every analysis includes a “view what was sent to the LLM” panel, so you can confirm what left the system.
No training; storage off
Requests are sent with OpenAI-side storage off (store=false), and OpenAI doesn’t train on API data. The default tier carries OpenAI’s standard 30-day abuse-monitoring retention; zero data retention is available for enterprise-scale deployments. We never sell or share your data.
Bring your own LLM endpoint
Run transcripts through your own provider contract instead of ours. Your API key is encrypted at rest (AES-256-GCM) and never shown in plaintext.
Turnkey self-hosting
Stand up the full Myc stack inside your own infrastructure with our turnkey self-serve installer — transcripts never leave your perimeter.
Role-scoped access & multi-tenant isolation
Every record is organization-scoped; cross-organization probes return 404. Elevated roles inherit MFA from your identity provider.
Encrypted in transit and at rest
TLS 1.2+ for all traffic. Customer content is encrypted at the application layer with AES-256-GCM under per-organization keys, with the root key held in AWS KMS; cloud-managed AES-256 volume encryption applies beneath that, including backups. Every administrative action is recorded to an append-only audit log.
Compliance posture
GDPR Data Processor and CCPA Service-Provider posture; a Data Processing Agreement is available for review.
Choose your privacy posture
Three deployment options, depending on what your security and legal teams need to be comfortable.
Standard SaaS
Hosted by us with the default redaction pipeline, encryption at rest, and per-organization isolation. The right default for most customers.
Bring your own LLM endpoint
Your org configures its own endpoint (Azure OpenAI, an enterprise OpenAI key, an OpenAI-compatible proxy, or Anthropic-direct). Transcripts touch only your provider contract.
Turnkey self-hosting
Run the entire stack in your own VPC via our turnkey self-serve installer. Transcripts never leave your infrastructure — for customers who require true vendor-zero-knowledge.
What we don’t claim
Honesty is part of trust. To be clear about today’s posture:
- SOC 2 Type II is in progress, not yet certified.
- On the default tier, our LLM provider’s standard 30-day abuse-monitoring retention applies. Zero data retention is available for enterprise-scale deployments (an enterprise provider agreement), not on the default tier today.
- In the standard SaaS tier, our worker reads transcript text momentarily to run the analysis — true vendor-zero-knowledge requires self-hosting.
- We don’t support PHI and aren’t HIPAA-compliant (no Business Associate Agreement).
- We don’t offer customer-managed encryption keys (CMEK/BYOK) or a choice of data region (US West only).
- An independent penetration test is planned, not yet completed.
Downloads for your security & legal teams
Free to download and share with your team — no email required.
Private from the very first upload.
Start with a redacted transcript, or bring your security team to a walkthrough.
Questions from your security team?
Email us and we’ll route it to the right person.
security@makingyourselfclear.com