Skip to content
EIWAVoice Operating System
Security you can trust

Your business.
Your clients. Protected.

You are handing EIWA your schedule, your client list and the notes you would never want read out loud. This page explains how that data is treated, and it is deliberate about what it does not promise.

Built on strong principles

Security at the core of everything we build.

Six principles that decide how EIWA is built. Each one describes a practice we can point at in the product, not a certificate we are waiting on.

  • Privacy by design
  • You own your data
  • Encrypted in transit
  • Named subprocessors
  • Client trust
  • Transparency
Privacy by design
We collect only what EIWA needs to run your bookings, clients and reminders. Your data is never sold and never used for ads.
You own your data
Your clients and your schedule belong to you. You can request an export or a full deletion at any time, and we act on it.
Encrypted in transit
Traffic between your phone, the client portal and EIWA runs over HTTPS. Access tokens are stored in the secure storage of your device.
Named subprocessors
The services that process data on our behalf are listed publicly, with what each one receives and why.
Client trust
Client links are single-purpose and expire. Consent and signatures are recorded with a timestamp so both sides have the same record.
Transparency
Our policies are written to be read, not to be survived. If something changes, the page says when and what.

Honest status

What we can and cannot claim today.

A page like this usually ends with a row of compliance badges. Ours does not, because we do not hold those certifications. Here is the whole picture instead.

True today

  • EIWA is an early-stage product in a private beta, and we say so on the page instead of in a footnote.
  • Traffic between your phone, the client portal and EIWA runs over HTTPS.
  • Every service that processes data on our behalf is named publicly, with what it receives and why.
  • You can ask for an export or a full deletion of your data at any time, and we act on it.

Not claimed

  • We are not SOC 2 certified and we are not ISO certified. We do not display badges for either.
  • We do not claim bank-level security, end-to-end encryption or a specific uptime figure.
  • We do not claim HIPAA compliance. If you handle health-adjacent information, read the acceptable use policy before you start.
  • We do not publish third-party audit reports, because there are none to publish yet.

The two documents worth reading before you start are the acceptable use policy and the subprocessors list. When any of the lines above changes, this page changes with it.

Documents

Learn more about our security and privacy practices.

Written to be read. If a sentence needs a lawyer to decode it, that is our mistake and we want to hear about it.

Found something here that does not hold up? Write to hello@eiwa.tech and we will fix the page or the practice, whichever one is wrong.

Your business deserves a secure foundation.

Join the private beta and see exactly how your schedule, your clients and your notes are handled.