What we do, and what we don't claim.
Both halves of this page matter. The second one is the reason to believe the first.
Tenant isolation
Every tenant table carries an organisation id, and row-level security policies scope reads to the organisation on your profile. Privileged background writes go through a separate client that must name the organisation explicitly.
Encryption
TLS in transit. Data at rest is encrypted by our database provider. Per-tenant channel credentials — bot tokens, access tokens — are encrypted with a separate key before they are stored, and are never readable from the browser.
Authenticated webhooks
Inbound webhooks are verified before their body is parsed: Meta's signature for Instagram, a per-connection secret token for Telegram. Requests that fail verification are rejected, not logged and processed.
Spend caps
Each workspace has a hard cap. On reaching it we pause the line rather than continue billing — enforced in the platform itself, not in a spreadsheet. Pausing actually stops inbound calls; it is not a flag we check later.
Your data stays yours
Calls, transcripts, contacts and appointments belong to your workspace. You can export them, and deleting your account deletes them.
Access control
The operator console is separate from the customer application and behind its own authentication. Customer sessions can never reach it.
The things we can't say yet.
We are not SOC 2 certified.
Not yet, and we will not imply otherwise. If your procurement needs a report today, we are the wrong vendor right now — tell us and we will say so.
We are not HIPAA compliant.
Do not route protected health information through Denku. Booking a dental appointment is fine; clinical detail is not.
We have no third-party penetration test to show.
When we commission one, the result goes on this page whichever way it reads.
Something here unclear, or something you need that isn't listed? Ask us directly — a person answers.