Trust

Security at Cordiul

Your prospect data, conversations, and recordings run through Cordiul. Here is how we protect them.

Last updated · 20 July 2026

Infrastructure

Cordiul runs on managed cloud infrastructure: our application is hosted on Vercel and our data lives in Supabase's managed Postgres. Both providers maintain their own independent security certifications, including SOC 2 Type II, and we inherit the physical and network controls they provide. Calling and SMS run on Twilio's telephony infrastructure.

Encryption

  • All traffic is encrypted in transit with TLS.
  • Data is encrypted at rest by our database and storage providers.
  • Credentials for connected CRMs and mailboxes are encrypted at the application level on top of at-rest encryption, and integrations use OAuth wherever the provider supports it, so we never store your CRM or mailbox passwords.

Access control

  • Every workspace's data is scoped to that workspace, enforced in the database layer.
  • Team access is invitation-based, and sessions are managed through our authentication provider.
  • Internal access to production data is restricted to the small set of people who operate the service, and used only to run and support it.
  • Inbound webhooks from telephony and email providers are signature-verified before we process them.

Data lifecycle

You can export your data while your account is active. Trial workspaces that do not convert are deleted within 30 days, and on termination you have 30 days to export before deletion. Deletion requests are honoured as described in our Privacy Policy.

AI and your data

Duo's research and writing run on enterprise AI providers under agreements that do not permit training on your data. Duo only sees the context needed for the task: the prospect being researched, your voice and tone settings, and the sequence being drafted.

Compliance posture

We are an early-stage company and do not yet hold our own SOC 2 or ISO 27001 certification; the managed providers underneath us do. We are happy to complete security questionnaires, sign DPAs, and walk your team through our architecture. Email hello@cordiul.com.

Reporting a vulnerability

If you believe you have found a security issue in Cordiul, email hello@cordiul.com with enough detail to reproduce it. We read these reports first, respond quickly, and will not take action against good-faith research.