How we protect your data and your business.

Manta workers handle the conversations, systems, and data your business already trusts you with. You decide what a worker may see, store, say and do, and you can change or revoke any of it at any time.

Contact security
You choose what is recorded

Callers hear your notice first. Decline and the call carries on with nothing kept.

Access is scoped and revocable

Each tool gets the narrowest permission the role needs. Cut any of it from either side.

Never training data

Your recordings, transcripts and customer records do not train public models.

One switch pauses everything

Every agent on the account stops within seconds and calls go to your fallback number.

Connect your calendar
Read your free slots
Create a booking
Your passwordNever sent
Revoke from either side.

Your data stays yours

Manta never sells, rents, or trains public models on your recordings, transcripts, or customer records. We hold scoped access to the tools you connect — your phone number, calendar, inbox, CRM, payments. You can revoke any connection inside Manta or from the tool itself.

Receptionist · limits
Book an appointment
Look up an order
Transfer to a person
Issue a refundNot in scope

Hard limits on every agent

Every worker runs inside limits you set before it does a single task: what it may say, what it may look up, what it may change, and when it must hand off to a person. The same limits run on the workers that run our own business. No exceptions, no override.

SOC 2 Type II
Audit under way · target Q3
At restAES-256
In transitTLS 1.3

SOC 2 underway

Type II audit in progress with target completion in Q3. AES-256 at rest, TLS 1.3 in transit, KMS-backed secret rotation, GDPR-compliant data handling, and OIDC-only deploys from CI.

How your data is actually handled.

When you connect a phone number, an inbox, a calendar, or a CRM to Manta, the connection is authorized through the provider's own consent screen. Manta never sees your password. We receive a scoped token limited to what the role actually needs: read the calendar, write a booking, look up a customer.

Recordings and transcripts belong to your business, not to us. You choose whether calls are recorded at all, and the agent plays the notice your jurisdiction requires before anything is stored. If a caller declines, the conversation continues with nothing kept.

Personal details a caller gives an agent are handled by category. Card details go straight to the payment processor and are never stored by us. Everything else is encrypted at rest, redacted in transcripts where you ask for it, and kept only for the retention window you set.

You can disconnect a tool or delete a workspace's recordings and transcripts at any time, from inside Manta. When you do, our access stops immediately and the data is purged from our backend within minutes.

ConsentThe caller hears your notice. Decline and nothing is written.
EncryptWhatever is kept is sealed at rest and in transit, by category.
RetainHeld for the window you set, redacted where you ask for it.
PurgeYou delete. Access stops at once and the data is gone in minutes.

Every agent passes these checks first.

The same controls that run on the workers running our own business run on every account. There is no manual override.

Before anything records
“This call may be recorded. Is that OK?”
CallerDeclinedNot recorded
audio.wav
transcript.json
The call carries on. Nothing is kept.

The infrastructure under the agents.

Twenty-two Terraform modules. Multi-AZ across us-east-1. Edge caching and WAF rules scoped per public surface. Secrets rotated on a cadence we can audit. No long-lived AWS keys in CI.

We run our own business on this exact stack every day. Nothing on a customer account runs on infrastructure we don't trust with our own work.

CloudAWS, us-east-1 primary with multi-AZ failover
Infra as codeTerraform, 22 modules, S3-backed remote state, DynamoDB locks
CI / CDGitHub Actions over OIDC, no long-lived AWS keys
EdgeCloudFront + AWS WAF per hostname, region-aware rules
SecretsAWS Secrets Manager + KMS rotation, scoped per service
EncryptionAES-256 at rest, TLS 1.3 in transit, HSTS preload
ObservabilityCloudWatch logs and metrics, structured tracing, alerting
Data residencyUnited States, with EU expansion planned for 2026