What’s live, what’s gated, what still needs setup.
Sovereign gives service businesses a contractor-first operating system for growth, communication, proof, and operations. This page names what is live, what is approval-gated, and what still needs customer setup.
Route protection
Protected app areas use session, tenant, admin, portal, webhook, API-key, or cron-secret controls depending on the route.
Approval gates
Autonomy is configured by action class. Sensitive money, destructive, legal/trust, and broad outbound actions use approvals or hard blocks; low-risk and explicitly enabled lifecycle workflows may run automatically.
Maturity labels
Integrations and modules are labeled live, beta, setup-required, or planned so customers know what is ready on day one.
Security posture
Auth redirects run at the framework edge for dashboard, admin, and login paths. Route handlers own the detailed controls: CSRF/origin checks, rate limiting, webhook signatures, tenant checks, cron secrets, portal sessions, and admin role gates.
Security response headers are configured at the Next.js layer. Provider error logging is designed to avoid full prompt or customer-context echo.
- Route protection inventory is maintained as a build-time artifact.
- Public API routes must be intentionally classified.
- Card details are entered on Stripe's hosted checkout — Sovereign servers never store card numbers.
- No third-party certification is claimed unless the audit is complete.
Data retention
Operational records such as leads, conversations, audit logs, payments, consent evidence, service evidence, and AI usage records are retained while needed to operate the account, support billing, resolve disputes, debug incidents, and preserve proof history.
Deletion requests move through the account privacy flow. Some records may remain for legal, security, fraud-prevention, tax, billing, or backup-retention reasons.
Privacy and data requests
Tenant data is not sold. Customer business data, founder platform metrics, and AI prompt context are treated as separate scopes.
Account export and delete-request flows exist for authenticated customers. Privacy requests can also be sent to privacy@trysovereignai.com.
Account deletion runs in two phases: a deletion request marks the account, and after a 30-day grace period an automated job permanently deletes the account record, writing an audit-log entry that documents the hard delete itself.
AI disclosure
Customer-facing voice, chat, and automated messages are AI-assisted when AI is involved. High-impact outputs should identify that assistance in the surrounding customer experience.
AI-answered phone calls open with a spoken disclosure — “Just so you know, you're speaking with an AI assistant.” — on both inbound and outbound calls. The disclosure wording lives in one shared module so every voice path uses the same reviewed copy.
Business profile fields, CRM records, transcripts, and imported content are treated as untrusted context for AI prompts. They may inform an answer, but they do not become instructions to the model.
- Customer data-backed answers should distinguish facts from assumptions.
- Owner approval is required before high-risk outbound, reputation, money, or legal/trust actions.
- Autonomy increases only after quality evidence and customer approval.
Human approval and autonomy
Agent actions pass through policy and entitlement checks before side effects. Low-risk internal work can run on its own. Explicitly configured chatbot replies, reminders, review requests, and lifecycle messages may also run automatically; broad outbound, destructive, legal/trust, and money-moving actions use stricter approval or hard-block policies.
Approval-backed actions create an account-scoped request that records the proposed action, payload, reviewer, and decision time. The activity trail and workflow configuration are the authoritative record of whether a particular action was automatic or approved.
Consent and communications
Sovereign records consent evidence where forms, chatbot, API, discovery conversion, or customer workflows collect email, phone, or outreach permission.
Marketing email and SMS workflows must support unsubscribe and opt-out handling. Suppression lists, quiet-hour checks, and owner approval gates are part of the operating model for outbound communication.
This page is not legal advice. Customers remain responsible for their own regulated outreach, privacy notices, and industry-specific obligations.
Call recording
Voice workflows should use approved call recording disclosure copy before recording is enabled. Disclosure requirements can vary by location and call type.
Recording is off by default and turns on only when the business has explicitly granted recording consent. When recording is on, callers also hear “This call may be recorded for quality.” — the platform never says a call may be recorded when it is not, and never records without saying so.
Call recordings, summaries, transcripts, and AI coaching outputs are treated as customer account data and should be handled with the same tenant-boundary controls as CRM records.
Subprocessors
The providers below support hosting, database, payments, communication, email, AI inference, telemetry, and analytics. Some subprocessors are used only when the related feature is configured.
| Subprocessor | Category | Purpose | Status |
|---|---|---|---|
| Vercel | Hosting | Application hosting, edge routing, deployments, and logs. | Core platform |
| Neon | Database | Postgres storage for tenant, workflow, and operating records. | Core platform |
| Stripe | Payments | Checkout, subscriptions, invoices, and payment webhooks. | Configured per account |
| Twilio | Voice and SMS | Phone numbers, calls, SMS, voice workflows, and messaging status. | Configured per account |
| Resend | Transactional and customer communication email. | Core email provider | |
| Anthropic | AI inference | AI-assisted reasoning, drafting, chat, extraction, and workflow support. | Feature-dependent |
| Groq | AI inference | Fast AI-assisted drafting and workflow inference when configured. | Feature-dependent |
| OpenRouter | AI inference routing | Optional fallback routing to configured third-party inference models. | Optional |
| Vapi | AI voice | Optional AI receptionist orchestration and call handling. | Configured per account |
| ElevenLabs | Voice synthesis | Optional generated voice audio for enabled call workflows. | Optional |
| SendGrid | Transactional and workflow email delivery when configured. | Feature-dependent | |
| Google and Meta | Advertising and analytics | Connected advertising, conversion, and analytics workflows when authorized by the customer. | Optional customer connection |
| Sentry | Error monitoring | Error capture, debugging context, and production reliability signals. | Operational telemetry |
| PostHog | Product analytics | Product usage analytics and feature insight when configured. | Optional analytics |
Kept current as vendors change. Privacy & data requests: privacy@trysovereignai.com.
Proof and claims
Sovereign does not invent testimonials, customer names, revenue, bookings, reviews, or integration status. Case-study metrics require source artifacts and permission.
Demo, beta, setup-required, and planned capabilities stay labeled until customer data and production evidence support stronger claims.
The exact disclosures, in plain words.
“Just so you know, you're speaking with an AI assistant.”
“This call may be recorded for quality.”
Recording stays off unless the business explicitly consents. The platform never claims a call is recorded when it isn’t, and never records without telling the caller.
Questions about security, data, or AI disclosure?
Privacy and data requests: support@trysovereignai.com
This trust center is an operational summary, not legal advice or a substitute for customer-specific counsel.