Skip to content
BirdSaid
Trust & legalPrivacyTermsVoiceprintsRecordingRefundsAcceptable useSubprocessorsSecurityContact

Safeguards

Security at BirdSaid

Last updated 28 August 2026 · Pre-launch posture

Current design

  • authenticated, tenant-owned transcript and audio access;
  • signed, expiring, individually revocable credentials for browser-recorder uploads;
  • AES-GCM encryption for stored voiceprint profiles, with tenant-separated keys and audio paths;
  • private, per-customer voice matching with no global index;
  • server-side jurisdiction, enrolment, size and count gates;
  • idempotent Stripe webhook handling and an append-only usage ledger;
  • HTTPS, restrictive website security headers and least-privilege Cloudflare bindings; and
  • automated format, type, test, extension-manifest and production-build checks.

Operational work before public launch

BirdSaid remains a demo. Public launch is gated on customer-authentication delivery, privacy-safe monitoring, external provider and company setup, and final security review. Self-service account export/deletion, tested D1 recovery with deletion tombstones, a content-free customer security-event trail, and per-account/IP processing controls are implemented.

Access to customer content

BirdSaid does not provide routine support access to recordings, transcripts or voiceprints. Customers use the product's own review, export and deletion controls. For a necessary privacy-rights request, security incident or binding legal obligation, access is limited to Praeco's designated infrastructure administrator, only to the minimum data required, and must be recorded in the applicable request or incident record. BirdSaid will reassess and add dedicated access logging before introducing any support tool that can open customer content.

Responsible disclosure

Please do not access another user's data, disrupt the service, perform denial-of-service testing, or retain personal data while investigating. A dedicated security email and response target will be published before public customer access. Until then, do not test the production demo without written authorisation.

No certification claim

BirdSaid does not currently claim ISO 27001, SOC 2, PCI certification, HIPAA compliance, or suitability for classified or regulated high-impact workloads. Stripe hosts card entry; BirdSaid does not intentionally store full card numbers.

BirdSaid

Praeco Innovation Ltd · Cyprus · HE 469106

PrivacyContact