The platform receives and transmits recordings via SFTP and secure APIs, ensuring end-to-end encrypted transfer. In addition, all communications use TLS 1.3/SSL, ensuring confidentiality and integrity when sending audio or other files. The methods used are SFTP and APIs encrypted under HTTPS/TLS 1.3.
The platform implements role-based access control (RBAC) based on the principle of least privilege, which applies to all processes, including data transfers. Furthermore, all access requires strong authentication, and connections are protected by MFA and secure credentials. This ensures that only authorized users can access sensitive information during transmission.
The platform secures all transmissions using TLS 1.3/SSL and mutual certificate validation, preventing interception or tampering in transit. Additionally, transfers via SFTP and encrypted HTTPS APIs ensure integrity and authenticity. The architecture incorporates firewalls, IDS/IPS, and network segmentation, mitigating MITM attacks and unauthorized access.
Yes, the transfer procedures are designed to handle large volumes of files without compromising security. eAlicia’s architecture uses asynchronous transfers encrypted via SFTP and APIs, designed to process large volumes of audio, text, and images without compromising security. All data transmission is protected by TLS 1.3/SSL, along with network segmentation and perimeter controls. Additionally, the data acquisition and processing mechanisms are modularized and orchestrated, allowing the system to handle high workloads without compromising data protection.
Patch management procedures are in place that prioritize security patches on systems that process Confidential Information (ICF) or Personal Data (DTPS). In addition, records of all audit, monitoring, and security activities are retained for 120 days, allowing for verification that updates have been applied correctly. These processes are integrated into a secure environment with strict access controls, ensuring that patches are installed in a controlled manner.
Patches are prioritized when they are security-related; otherwise, they are applied every 3 months. Audit, monitoring, and security logs are retained for 120 days, which allows us to verify that the patches were applied correctly.
The platform maintains separate development, test, and production environments, which means that changes and updates—including patches—are first validated in non-production environments. In addition, the CI/CD model requires unit, functional, and integration tests, as well as security reviews, before any deployment to production. Therefore, there are indeed controls in place to ensure that patches are tested and validated beforehand.
The application itself automatically updates virus signatures on a scheduled basis, with centralized management.
The platform features continuous 24/7 monitoring through the SOC and systems such as IDS/IPS, PRTG, and centralized logs, which involves ongoing security and infrastructure analysis. In addition, internal audits, penetration testing, and periodic risk assessments are conducted to detect vulnerabilities. Although no specific frequency is specified for each system, the Security Policy confirms continuous and recurring controls across the entire infrastructure.
Backup media are encrypted, and data in transit uses TLS 1.3 with a 2048-bit RSA key exchange. In addition, credentials are encrypted using AES-256. Data is stored encrypted at rest.
All backups are encrypted. TLS 1.3 + RSA-2048 is used for data in transit, and AES-256 is used for credentials. Therefore, the backups are encrypted.
Credentials are encrypted using AES-256.
Access to encryption keys is restricted exclusively to authorized IT personnel, in accordance with strict security controls. Only these users may manage them, applying RBAC, the principle of least privilege, and segregation of duties, ensuring that no other user or department has access to these keys. In addition, all actions related to their use or administration are logged and audited to ensure traceability and control.
All data in transit is encrypted using TLS 1.3 with 2048-bit RSA, including internal transfers between servers and data flows to and from backup systems. In addition, communications between zones within the architecture use SSL certificates and mutual authentication, ensuring integrity and confidentiality. Therefore, mandatory encryption is in place for all data in transit, including data related to backups.
TLS 1.3 with RSA-2048 and AES-256 encryption is used for credentials, in accordance with industry standards and frameworks such as GDPR, ISO 27001, ENS, SOC 2, and NIST SP 800-53. The encryption complies with the aforementioned security and data protection frameworks and regulations (GDPR, LOPDGDD, AI Act, etc.).
In the event of the loss or compromise of an encryption key, an internal incident response procedure—managed by the IT team—is implemented. This process includes the immediate revocation of the affected key, its secure rotation or regeneration, and verification that there is no impact on data integrity or availability. All actions are logged and audited, ensuring traceability and compliance with security policies.
Each customer’s data is stored in separate databases, and there are distinct development, pre-production, and production environments, each with its own control mechanisms: firewall policies, schema separation, specific VLANs, and RBAC controls per instance.
Access is protected through role-based access control (RBAC), applying the principle of least privilege to limit which users can access each environment or database. In addition, robust authentication is required, including strong passwords and lockouts for failed login attempts. All access is logged and audited, and restricted solely to roles defined for each system or resource.
Yes. We use Subversion and maintain system logs.
The servers retain audit, monitoring, and security logs for 120 days, including data access, insertions, and modifications. In addition, the platform features continuous monitoring (24/7 SOC/NOC) and centralized logging to detect unauthorized changes or access. All logs are role-based and form part of internal audit and compliance processes.
Each separate environment protects sensitive data through encryption at rest and in transit (TLS 1.3, RSA-2048), along with role-based access control (RBAC) that strictly restricts who can view or modify information. In addition, all actions are recorded in auditable logs, and personal data is anonymized or pseudonymized before any processing takes place.
The platform features an internal SOC that monitors 24/7, generating automatic alerts in the event of any anomaly or incident in any separate environment. In addition, there are documented incident management and response procedures, aligned with ISO 22301 and ISO 27001, that include analysis, containment, and communication with the customer. All events are recorded in auditable logs, enabling investigation and complete traceability.
Anonymization is performed using automated processes that detect patterns and entities identifying personal data and replace them with irreversible identifiers. This substitution is tailored to each case, upon request, based on the information to be protected (for example: account numbers, ID numbers, numerical codes, names, dates, or sensitive references such as medical information). When requested by the client, this data may also be pseudonymized prior to processing.
Through substitution processes, the rate is 100%.
AI models are isolated on the private network, with no connection to external services, and protected by network segmentation, firewalls, WAFs, and IDS/IPS. Access is controlled through RBAC, MFA, and least-privilege policies, with full traceability of all actions. All communications are encrypted using TLS 1.3/SSL, and changes go through a secure CI/CD pipeline that includes validation and vulnerability scanning. In addition, a 24/7 SOC monitors for any intrusion or tampering attempts. Only authorized IT department personnel have access to the servers hosting the AI models.
Integrity and confidentiality are ensured through isolated environments, segmentation between training, validation, and production, TLS 1.3/SSL encryption, and RBAC+MFA access control. Deployments go through a secure CI/CD pipeline that includes audits and vulnerability scans, and a 24/7 SOC monitors for any anomalies or tampering attempts.
Yes, at least once a month. eAlicia conducts periodic risk assessments, ethical audits, and bias reviews on all AI models, including generative, analytical, and transcription models. These analyses aim to detect vulnerabilities, deviations, discriminatory biases, or anomalous behavior. In addition, monthly calibrations and validations with human oversight are performed to ensure safety and fairness. All of this is part of a formal program of continuous monitoring and compliance with the AI Act and GDPR, preventing accidental exposure of sensitive data.
Unit tests are performed to validate the anonymization of the requested data.
At the customer’s request (though this is not always necessary), data is anonymized before being sent to the AI models, with all personal data replaced by irreversible identifiers. In addition, ethical audits, periodic bias reviews, and human oversight are conducted to ensure that no sensitive data is embedded in or left as residual data in the models.
It is not necessary to apply differential privacy because models are not trained using customer data. Queries to the models (LLMs) are used solely to analyze the context received at that moment, with no retention or learning from that information. Furthermore, the data can be anonymized beforehand, and the analysis focuses exclusively on agent behavior, conversations, and the quality of interactions, thereby avoiding any risk of exposure.
Compliance is ensured through a fully isolated architecture, where all data is processed exclusively within our private network and is never sent to external services. Queries to the models are made solely from eAlicia’s internal processes, with no possibility of external access, ensuring absolute control over the flow of information. Furthermore, upon the customer’s request, data can be anonymized or pseudonymized prior to processing, thereby strengthening privacy protection and ensuring compliance with regulations such as the GDPR and LGPD.
Open-source and proprietary models running locally.
Our AI is based on auditable open-source models (Whisper, Llama, Mistral) and proprietary models trained in-house, all running exclusively on our servers within the data center. The underlying technology uses frameworks such as PyTorch, TensorFlow, and HuggingFace, installed locally and without connection to external services. We do not use third-party APIs or public clouds, so no data is sent outside our infrastructure. All processing takes place in private, isolated environments under our full control. This guarantees complete confidentiality and data sovereignty.
The tool is closed by design, because all AI models run exclusively on our private, isolated infrastructure, which is disconnected from external services. Each customer’s data is processed in logically separate instances, with independent databases that prevent any mixing between projects. There is no continuous training or cross-learning: the models do not reuse information or incorporate customer data into their internal operations. All access is regulated by RBAC, auditing, and authorization workflows, ensuring that only authorized personnel can interact with the environments. Furthermore, contractual commitments reinforce that the client’s information is used exclusively for their own service and is never shared or applied outside their scope.
The platform protects models through complete isolation within the private network, with no exposure to external services, along with strict segmentation between training, validation, and production. In addition, it employs firewalls, WAF, IDS/IPS, TLS 1.3 encryption, RBAC, MFA, and 24/7 SOC monitoring, preventing unauthorized access or data extraction attempts. Finally, ethical audits, periodic bias reviews, and full traceability throughout the model’s lifecycle ensure that sensitive information cannot be inferred or extracted.
Yes. A distinction is made between original recordings and processed data, each with different retention policies (for example, audio recordings are retained for a maximum of 3 months, and data is retained only for auditing purposes). Therefore, it is necessary to have a detailed understanding of both policies to ensure secure deletion and regulatory compliance.Data is securely deleted upon termination of the contract or at the customer’s request, ensuring compliance with the GDPR and LGPD.
Audio recordings are retained for a maximum of 3 months and may only be retained longer if the client expressly requests it. The processed data (transcripts, analyses, etc.) are retained only for as long as necessary for audit purposes. Any extension of this period requires a request and explicit authorization from the client.
Yes, calls are recorded.
The platform uses AI transcription models installed and run on-premises, within a private environment, without sending any information to external services.
The models used include open-source models such as Whisper, as well as variants and specific models developed in-house, all of which run exclusively on eAlicia’s private infrastructure. These models process the audio within the data center, without any connection to third parties and with full control over the data flow.
The platform ensures secure data disposal through verifiable destruction once the intended purpose has been fulfilled, including certified reports upon customer request. In addition, backups are immutable, encrypted, and subject to limited retention, ensuring that no residual data remains after the end of its lifecycle. The process is carried out within private environments that are controlled in accordance with the GDPR, LOPDGDD, and ISO 27001.
Backups are retained only for the specified period (90 days) and are then deleted in accordance with internal business continuity and security policies. The copies are immutable, encrypted, and periodically verified, ensuring that no information remains beyond the authorized retention period. Therefore, yes: the deletion process includes the removal of data from backups once their retention period has expired. Data is securely deleted upon contract termination or at the customer’s request, ensuring compliance with the GDPR and LGPD.
The servers are housed in a data center, to which only the CTO and a select few technicians have access, using an access card and a physical key.
The data center maintains a secure environment through advanced certifications and standards (ISO 27001, high-level ENS, GDPR, ISO 22301, ISO 27017), as well as reinforced physical infrastructure, biometric access control, CCTV, and 24/7 surveillance. It also utilizes fire detection systems, electronic doors, biometric scanners, and burglar alarms to ensure perimeter protection. All access is documented and controlled, ensuring traceability and ongoing compliance.
Backups are stored on the data center’s own NAS, and a second copy is also made at an alternate geographic location. As for critical infrastructure, the platform maintains replicated backups between the VODAFONE and COLT data centers, located in Barcelona and Madrid, ensuring resilience and continuity.
We do not use tapes. Backups are stored on NAS devices within the data center itself, which means disk-based storage or storage arrays, not tapes. In addition, there is a second copy at an alternate geographic location, also managed using similar storage infrastructure.
Download PDF for further information on Safety.
eAlicia Worldwide Quality | 2012–2025 © All rights reserved.