Trust
Security is not an upsell.
Last updated · 26 August 2026
Redaction, erasure, audit and role-scoped access ship on every plan — the £79 desk and the enterprise desk run the same engine. Every claim on this page is wired to a mechanism that exists in production. Nothing here is aspiration, and the last section lists what we deliberately do not claim.
The mechanisms
Every fact the receptionist can say enters through a single signed path: versioned, stamped with its source and approver, previous versions archived — never silently overwritten. If it is not in an approved cell, it is not said. She refuses rather than invents.
Every reply, quote, refusal and booking is recorded with its reason and is exportable. An operator, a customer, or the ICO can be shown exactly why she said what she said. A desk without a ledger is a prompt with a voice.
Key-safe, alarm and entry codes are scrubbed by pattern before they can reach summaries or exports. Phone numbers and emails are redacted in public audit views. This runs in code, on every message — not by policy document.
A right-to-erasure request (UK GDPR, Article 17) is executed as a single operation: messages, appointments and quotes deleted, identifiers anonymised, the audit trail kept lawful but nameless.
Old message content is deleted on an automatic daily sweep. Data we no longer need is data we no longer hold.
Text STOP to any Receptionist number and the opt-out is honoured deterministically — it is not a prompt the AI might forget, it is a gate the message cannot pass. START opts back in. PECR is operating policy here, not an aspiration.
Three credential tiers: the business owner's portal key, a staff key for the private knowledge tier, and the platform master key. The public brain is read-only. Every door is rate-limited; unsigned webhook traffic is refused at the edge.
Conversations are processed by contracted AI providers under API terms that do not use your data to train their models. Your customers' words answer your customers — they do not become anyone's training set.
What we do not claim
We have not purchased a SOC 2 audit. The architecture keeps audit-grade evidence by design — the ledger, signed provenance, scoped keys — so when an enterprise agreement calls for the badge, the audit certifies what already exists. We will not print the badge before the auditor does.
We do not publish an uptime percentage we have not measured over a meaningful period. When we claim a number, it will be a measurement, not a marketing figure.
Receptionist serves businesses globally, the United States included. US healthcare specifically requires a signed Business Associate Agreement and certified controls — until we hold those, we do not print the letters HIPAA, and we say so plainly. Every other American business runs on the same engine today, with opt-outs enforced to TCPA standard and deletion honoured for anyone who asks.
Posture
Receptionist is British-built and UK-first — and global by default. The mechanisms above are not geo-gated: redaction, erasure, the ledger and the opt-out gate run identically for a desk in London, Lagos, or Los Angeles. We hold every desk to the strictest standard we operate under, wherever it happens to sit — UK and EU desks run under UK/EU GDPR and PECR; US desks get STOP enforcement aligned with the TCPA and rights handling in the spirit of the CCPA — access, deletion, and no sale of personal data — honoured for every customer whether or not local law compels it.
AIFORCE Technology Group Ltd is registered in England & Wales (no. 17016705), with the ICO as supervisory authority. Sub-processors — hosting, database, AI and messaging carriers — are contracted for the single purpose of running the desk; the current list is available on request. Businesses can export their customers, conversations and knowledge at any time, and leave with their data.
See the engine itself on the Liability Engine — the same gates and ledger described here, live. Report a security concern: cloudaiforce@gmail.com — we read every report.