Othello logo

Trust and security for real-time AI sales coaching

Real-time mission control, on-screen for every sales call.

Othello is an execution layer for modern revenue teams.

How Othello handles call data

Othello is an in-call AI tool, so the first question security and vendor-risk reviewers ask is what happens to the live conversation. Othello's published posture answers that directly.

Does Othello record calls?

Othello provides coaching without recording conversations. In regulated environments, it functions without storing audio, transcripts, or PII.

Does Othello join the call as a participant?

No. Othello is invisible by design. It runs on the rep's desktop and surfaces guidance on the rep's screen without joining the meeting as a participant or bot.

Can Othello run with recording and storage turned off?

Yes. Othello can deliver live coaching while audio and transcript storage are disabled, which is the configuration used in environments where call content cannot be retained.

How is consent handled?

Automatic customer consent prompts are available.

How is access to data controlled?

Strict access controls, a security-first architecture, and compliance-aligned infrastructure govern all access. AI processing is isolated and governed by strict data usage controls.

This is the architecture distinction for an in-call tool: guidance is generated in the moment, and in regulated configurations the conversation does not need to be recorded or stored for the product to work.

Training-data commitments

From Othello's published privacy policy and trust FAQ:

Do you train models on customer data?

"No. Customer data is never used to train public or shared models. All AI processing is isolated and governed by strict data usage controls."

Do you use third-party platform data for general-purpose model training?

"We do not use Third party platform data to train or improve general purpose models for use outside the Services or by other customers."

Do subprocessors train on Othello's customer data?

"We do not permit subprocessors to use Third party platform data for their own independent model training, even in de-identified form."

Compliance certifications and audit reports

  • SOC 2 Type 1 — compliant. Full report available under procurement review.

  • SOC 2 Type II — in progress.

  • ISO 27001 — compliant. Certificate available under procurement review.

  • ISO 42001 (AI management system) — in progress.

  • GDPR — in progress.

  • Penetration test — Othello commissions an annual third-party penetration test. Most recent report available under procurement review.

Data processing, subprocessors, and residency

These are the artifacts an enterprise procurement review asks for. Each is available under procurement review from compliance@othello.ai or through the Othello trust center.

Data Processing Agreement (DPA). Available under procurement review. Covers the processing terms, roles, and audit rights an enterprise data-protection team reviews before signature.

Named subprocessor list. Available under procurement review. Identifies the third parties involved in delivering the service. As stated above, subprocessors are not permitted to use third-party platform data for their own independent model training, even in de-identified form.

Data residency options. Available under procurement review. Othello supports residency discussion as part of procurement for teams with specific regional requirements covering production data, backups, and processing.

Contractual no-training commitment. Available under procurement review, and reflected in the published privacy-policy language quoted above.

Audit log retention policy and OAuth scopes documentation are likewise available under procurement review.

Where Othello sits under the EU AI Act

Security reviewers in EU-touching organizations ask how an in-call AI tool is classified under the EU AI Act. Othello's posture on the questions that drive that classification:

  • Intended purpose. Othello is a sales-execution support tool. It surfaces guidance to a sales rep during a business-to-business sales conversation. Its intended purpose is helping a salesperson conduct a better sales call.

  • Use it is built for. Othello is positioned for the sales motion. It is offered as a sales-coaching tool, distinct from the HR, hiring, performance-evaluation, and workforce-management uses the Act treats as high-risk under Annex III.

  • Transparency. Automatic customer consent prompts are available, supporting the transparency expectations that apply to AI systems interacting with people.

A formal Article 6 classification statement is part of Othello's compliance documentation available under procurement review. Reviewers preparing for the Act's August 2026 milestones can request it through compliance@othello.ai.

Security controls

Othello operates 92 security controls documented at the Othello trust center, organized across the following categories:

  • Asset management

  • Business continuity and disaster recovery

  • Capacity and performance planning

  • Change management

  • Cloud security

  • Compliance

  • Configuration management

  • Continuous monitoring

  • Cryptographic protections

  • Cybersecurity and data privacy governance

  • Data classification and handling

  • Endpoint security

  • Human resources security

  • Identification and authentication

  • Incident response

  • Information assurance

  • Mobile device management

  • Network security

  • Physical and environmental security

  • Project and resource management

  • Risk management

  • Secure engineering and architecture

  • Security awareness and training

  • Security operations

  • Third-party management

  • Threat management

  • Vulnerability and patch management

  • Web security

  • ISMS monitoring, measurement, and continual improvement

Representative controls within these categories include encryption at rest and in transit, multi-factor authentication for all production access, least-privilege access provisioning, quarterly access reviews, centralized log collection, multi-availability-zone backups with periodic restore testing, annual incident response and business continuity testing, automated SAST scanning of code changes, peer review and approval for production deployments, environment and tenant segmentation, annual employee and contractor security awareness training, background screening, annual third-party penetration testing, and a documented vendor management program with annual vendor reviews.

Policy library

Othello maintains 41 documented information security and data protection policies, reviewed annually:

Information security and operations

  • Information Security Policy

  • Information Security Management System (ISMS) Manual

  • ISMS Statement of Applicability

  • ISMS Communication Plan Policy

  • Access Control and Termination Policy

  • Acceptable Use Policy

  • Personnel Security Policy

  • Physical Security Policy

  • Network Security Policy

  • Baseline Hardening Policy

  • Change Management Policy

  • Incident Response Policy

  • Breach Notification Policy

  • Business Continuity and Disaster Recovery

  • Vendor Management Policy

  • Risk Assessment and Treatment Policy

  • Risk Treatment Plan

  • Business Impact Assessment Policy

  • Chief Information Security Officer (CISO) Policy

  • Company Handbook

Data protection and privacy

  • Data Classification Policy

  • Data Handling Policy

  • Data Protection and Encryption Policy

  • Data Retention and Disposal Policy

  • Data Protection, Accountability, and Privacy by Design Policy

  • GDPR Information Security and Access Control Policy

  • International Data Transfer Policy

  • Binding Corporate Rules (BCRs) Policy

  • Records of Processing Activities (ROPA) Policy

  • Data Subject Rights and Request Policy

  • Consent Withdrawal Policy

  • Right to Object Policy

  • Principles Relating to Processing of Personal Data

  • Sensitive Data Processing and Impact Assessment Policy

  • Criminal Data Processing Policy

  • Age Verification and Parental Consent Policy

  • Automated Individual Decision-Making, Including Profiling

  • International Cooperation for the Protection of Personal Data

Governance charters

  • Board of Directors Charter

  • Oversight Committee Charter

  • Risk and Governance Executive Committee Charter

  • Information Technology Leadership Committee Charter

Platform and partner certifications in progress

  • Salesforce AppExchange listing in progress. The Othello + Salesforce integration is in production today; the AppExchange certification adds Salesforce-side review and listing in the AppExchange marketplace.

Trust documentation available under procurement review

Available on request from compliance@othello.ai or through the Othello trust center:

  • SOC 2 Type 1 Report

  • ISO 27001 Certificate

  • Penetration Test Report

  • Data Processing Agreement (DPA)

  • Named subprocessor list

  • Data residency options

  • Audit log retention policy

  • Contractual no-training commitment

  • EU AI Act Article 6 classification statement

  • OAuth scopes documentation

  • Any of the 41 policies listed above

Security and compliance contact

For security questionnaires, audit reports, policy access, or incident reporting: compliance@othello.ai

Continue reading