Your data stays yours
Manta never sells, rents, or trains public models on your recordings, transcripts, or customer records. We hold scoped access to the tools you connect — your phone number, calendar, inbox, CRM, payments. You can revoke any connection inside Manta or from the tool itself.
Hard limits on every agent
Every worker runs inside limits you set before it does a single task: what it may say, what it may look up, what it may change, and when it must hand off to a person. The same limits run on the workers that run our own business. No exceptions, no override.
SOC 2 underway
Type II audit in progress with target completion in Q3. AES-256 at rest, TLS 1.3 in transit, KMS-backed secret rotation, GDPR-compliant data handling, and OIDC-only deploys from CI.
How your data is actually handled.
When you connect a phone number, an inbox, a calendar, or a CRM to Manta, the connection is authorized through the provider's own consent screen. Manta never sees your password. We receive a scoped token limited to what the role actually needs: read the calendar, write a booking, look up a customer.
Recordings and transcripts belong to your business, not to us. You choose whether calls are recorded at all, and the agent plays the notice your jurisdiction requires before anything is stored. If a caller declines, the conversation continues with nothing kept.
Personal details a caller gives an agent are handled by category. Card details go straight to the payment processor and are never stored by us. Everything else is encrypted at rest, redacted in transcripts where you ask for it, and kept only for the retention window you set.
You can disconnect a tool or delete a workspace's recordings and transcripts at any time, from inside Manta. When you do, our access stops immediately and the data is purged from our backend within minutes.
Every agent passes these checks first.
The same controls that run on the workers running our own business run on every account. There is no manual override.
The infrastructure under the agents.
Twenty-two Terraform modules. Multi-AZ across us-east-1. Edge caching and WAF rules scoped per public surface. Secrets rotated on a cadence we can audit. No long-lived AWS keys in CI.
We run our own business on this exact stack every day. Nothing on a customer account runs on infrastructure we don't trust with our own work.



