This page summarizes Copper's security posture for business customers reviewing us as a vendor. For the underlying legal terms see our Terms of Service and Privacy Policy. Questions: info@joincopper.io.
At a glance
- US-based hosting on Vercel and Supabase.
- Data encrypted in transit (TLS) and at rest (AES-256) end to end.
- Postgres row-level security isolates each tenant's data at the database layer.
- No customer data is used to train AI or machine-learning models — ours or our providers'.
- Small US team; production database access is limited to a restricted set of authorized engineers.
Data we handle
Copper processes the following categories of data on your behalf:
- Business configuration. Business name, hours, services, pricing ranges, FAQs, brand voice notes, transfer number, uploaded knowledge-base documents, and website content crawled during onboarding.
- Call data. Inbound call audio, recordings, machine-generated transcripts, and post-call summaries.
- SMS content. Text of inbound and outbound SMS conversations between callers and the AI or dashboard operator.
- Contact records. Caller phone numbers, names, and other details a caller shares during a call or text.
- Calendar data. When Google Calendar is connected, the specific event and free/busy scopes described in our privacy policy.
- Billing. Stripe manages cardholder data. Copper never sees or stores full card numbers.
- Application logs. IP addresses, request paths, error traces, and other operational metadata used for debugging and abuse prevention.
Encryption
In transit. All connections to Copper and between Copper and our sub-processors travel over TLS. Public browser traffic uses TLS 1.2 or higher.
At rest. Our primary database (Supabase Postgres) encrypts data at rest using AES-256. Google OAuth refresh and access tokens are additionally encrypted at the application layer using AES-256-GCM before being written to the database. The application-layer key is stored as an environment secret outside the database, so a database compromise alone does not expose Google tokens.
Access controls
- Tenant isolation.Postgres row-level security policies scope every business record to the business that owns it. One customer cannot query another customer's calls, contacts, transcripts, or configuration through the application.
- Least privilege at runtime. The application connects to Postgres as a scoped role that respects the RLS policies, not as a superuser.
- Administrative access. Production database and infrastructure consoles (Supabase, Vercel, Stripe, Twilio, Vapi) are accessed only by a small number of authorized team members using vendor-managed authentication.
- Audit trail. Application-level actions with material impact (deployments, deprovisioning, teardown) are logged.
Sub-processors
Copper is built on top of established SaaS providers. Each sub-processor receives only the data it needs to perform its function. Our current sub-processors are Vercel (web hosting), Supabase (database and authentication), Twilio (telephony and SMS), Vapi (voice AI orchestration and text-to-speech), Anthropic (Claude language model), Deepgram (speech-to-text), OpenAI (embeddings for knowledge-base search), Stripe (billing), Resend (transactional email), and Google (Calendar API, when connected by the customer). Each vendor is contractually limited to processing data on our behalf. See our Privacy Policy for the full list and what each vendor processes.
AI and model training
We do not train models on customer data — we don't operate our own foundation models. Our AI providers (Anthropic, OpenAI, Deepgram, Vapi) are used under their commercial API terms, which prohibit training on customer API traffic without an explicit opt-in. We have not opted in and will not.
Data residency
Copper's primary application and database run in US data centers operated by Vercel and Supabase. Sub-processors are US companies operating US-based infrastructure.
Retention and deletion
Our retention windows are documented in the Privacy Policy. In summary: call recordings, transcripts, and SMS conversations are deleted within 30 days of account cancellation, and remaining account data within 90 days, unless we are required to retain something for legal or tax purposes. You can request data export or deletion at any time by emailing info@joincopper.io.
Backups and continuity
Our database is hosted on Supabase, which provides managed automated backups and point-in-time recovery. We do not currently publish a formal recovery time objective (RTO) or recovery point objective (RPO) for the self-serve tiers; enterprise commitments are available under the Custom tier.
Incident response
If we confirm a security incident that affects customer data, we will notify affected customers promptly — aiming for notice within 72 hours of confirmation — with what we know at the time of notification and what we are doing about it. Notice will be sent to the account owner email on file. To report a suspected incident on your side (compromised login, unusual dashboard activity), email info@joincopper.io as soon as you can.
Compliance posture
We're a small US company operating with practices standard for a SaaS product at our current stage. To be direct about what we do and don't hold today:
- SOC 2. We do not hold a SOC 2 report at this time.
- HIPAA. Copper is not a HIPAA covered entity or business associate at the Solo or Business self-serve tiers. We do not sign Business Associate Agreements at self-serve. If your use case requires HIPAA compliance, email us about the Custom tier before signing up.
- PCI DSS. Cardholder data is handled entirely by Stripe. Copper is not in-scope for PCI DSS as we do not receive, store, process, or transmit cardholder data.
- Telecommunications and SMS. Consumer SMS is sent only after prior express consent (documented in our Terms of Service). Opt-out keywords are honored at the carrier layer. Copper handles A2P 10DLC brand and campaign registration with The Campaign Registry so tenants can use business-line SMS immediately.
- Google API Services User Data Policy. Our use of Google Workspace data (Calendar) adheres to the Limited Use requirements. Details in the Privacy Policy.
Your responsibilities (shared responsibility)
Copper secures the platform and the vendor stack underneath it. You are responsible for how you use the service and for the aspects of security that live on your side of the boundary, including:
- Account access.Choosing a strong, unique password; keeping login credentials confidential; and not sharing dashboard access with anyone who shouldn't have it.
- AI configuration. The AI represents your business based on what you configure — services, pricing, brand voice, emergency criteria, transfer policy, uploaded documents, and crawled website content. You are responsible for what it says on your behalf and for reviewing that content periodically.
- Sensitive data in your KB.Do not upload documents containing sensitive personal information (Social Security numbers, full payment card numbers, protected health information, driver's license numbers, or the equivalent). The knowledge base is designed for public-facing business content (service catalogs, policies, FAQ material), not confidential records.
- Industry-specific compliance. If your business is subject to industry regulation (HIPAA for healthcare, PCI DSS for payment card data, GLBA for consumer financial services, state-specific privacy laws, professional licensure rules), you are responsible for ensuring your use of Copper is compatible with those obligations. Ask us before signing up if you have doubts.
- Caller notice and consent. Some US states require two-party consent for recorded calls. Copper records inbound calls by default; you are responsible for ensuring appropriate notice to callers based on the jurisdictions where you and your callers are located.
- SMS content. You are responsible for ensuring your use of the SMS features complies with TCPA, CAN-SPAM, and carrier acceptable-use requirements. Prohibited categories are listed in our Terms.
- Incident notification to us. If you suspect your Copper account has been accessed by someone unauthorized, notify us at info@joincopper.io promptly so we can help contain it.
Reporting a vulnerability
If you discover a security vulnerability in Copper, please report it to info@joincopper.io with the details we would need to reproduce the issue. We appreciate responsible disclosure and will not pursue action against good-faith security research that avoids service disruption, respects other customers' data, and gives us reasonable time to remediate before public disclosure. Do not test against production without prior written authorization.
Questions
Email info@joincopper.io. Diligence questionnaires (SIG Lite, CAIQ, custom vendor forms) can be sent to the same address — we'll respond within a reasonable timeframe.
