Nimitai Security & Trust

Nimitai protects customer call data with TLS 1.3 in transit, AES-256 at rest, SSO with MFA, role-based access, and configurable US, EU, and India data residency. Nimitai is GDPR-aligned and CCPA-aware, and a security review is available on request.

How Nimitai protects your sales call data

Eight areas covering encryption, access, residency, compliance, and incident response. Built for revenue teams selling into regulated buyers.

Data encryption

  • TLS 1.3 for all data in transit between client and backend services.
  • AES-256 encryption at rest for call recordings, transcripts, and metadata.
  • Encryption keys managed in AWS KMS with strict role-based access policies.

Access controls

  • SSO via SAML 2.0 and OIDC (Google Workspace, Microsoft Entra ID, Okta).
  • Mandatory multi-factor authentication for all admin accounts.
  • Role-based access control: admin, manager, rep, and read-only auditor roles.
  • Session timeout and forced re-authentication after 12 hours of inactivity.

Data residency

  • US region (AWS us-east-1) for North American customers.
  • EU region (AWS eu-west-1, Ireland) for European customers, GDPR-aligned.
  • India region (AWS ap-south-1, Mumbai) for APAC customers.
  • Customer data does not cross regions without explicit written consent.

Compliance status

  • GDPR-aligned: Data Processing Agreement available on request.
  • CCPA-aware: California consumer data subject requests supported.
  • Security review available on request for procurement and vendor-risk teams.

Call recording compliance

  • Configurable per-region disclosure settings for one-party and all-party consent jurisdictions.
  • Recording policy controlled by workspace admins.

Data retention and deletion

  • Configurable retention window: 30, 90, 180, 365 days, or custom.
  • Default retention: 365 days from call date.
  • Customer-initiated deletion within 24 hours of request.
  • End-of-contract deletion: all customer data purged within 30 days unless extended retention is contractually agreed.

Subprocessors

  • AWS (compute, storage, KMS): US, EU, and India regions.
  • OpenAI (transcription and summarization): zero data retention API contract.
  • Anthropic (coaching and insight generation): zero data retention API contract.
  • Full subprocessor list and update notifications available on request.

Incident response

  • 24-hour customer notification for any confirmed security incident affecting customer data.
  • 72-hour notification to relevant supervisory authorities under GDPR Article 33 where applicable.
  • Documented incident response playbook with on-call rotation.
  • Post-incident review report shared with affected customers within 14 days.

Call recording: built around state and country consent law

US recording law splits states into one-party and all-party consent. Some US states require all-party consent, including California, Florida, Illinois, Maryland, Massachusetts, Pennsylvania, and Washington. The EU and UK require informed consent under GDPR and UK GDPR. India recognizes one-party consent under the IT Act subject to evolving DPDP Act guidance.

Nimitai’s disclosure settings are configurable per call region, so admins can set the recording policy that fits each jurisdiction. Customers remain responsible for obtaining consent under applicable law, as set out in our Terms of Service.

Compliance posture, stated plainly

Nimitai is GDPR-aligned and CCPA-aware today. A security review is available on request. We do not claim certifications we do not hold; if a procurement reviewer asks for a control we have not yet attested, we will say so and propose an alternative compensating control.

Security contact and responsible disclosure

Reach the Nimitai security team at security@nimitai.com. We acknowledge all reports within 24 hours and provide a remediation timeline within 5 business days. For a Data Processing Agreement, the subprocessor list, or a security review, email the same address with your company name and procurement context.

See also our Privacy Policy, pricing, and the research behind the product in our talk-ratio study.

Renai Technologies Private Limited

Security: security@nimitai.com