CoveCall is built so a caller can never change your agent's behavior, extract its instructions, or pull private data. Here's how we keep your business and your callers safe.
Your agent's instructions are compiled server-side. Caller speech is delivered as fenced, untrusted data — never as commands.
The agent can't recite its prompt, your private number, or internal notes. There's simply no tool for it to do so.
“Ignore all previous instructions” and similar attempts are refused, flagged, and logged for your review.
Google sign-in, email/SMS one-time codes, and authenticator-app TOTP MFA for every account.
Encryption in transit and at rest, least-privilege access, row-level security, and audit logging.
SOC 2-ready architecture, DPA available, configurable retention, PII redaction, and call-recording consent controls.
The hard part of a phone agent isn't answering — it's staying in role when someone tries to talk it off-script. We treat every word a caller says as untrusted input.
Live example
We're happy to share our subprocessor list, DPA, and architecture overview.