Afterclerk/Security
For whoever checks the build

How it’s built, where the data goes, and what it never touches.

Owners can skip this page. It is for your IT person, your compliance lead or your counsel: the steps every conversation goes through, the accounts it runs in, and the limits written into every build.

The steps

Every step a conversation goes through.

afterclerk pipeline · the design we build tomade-up records · sandbox
  • read
  • model call
  • human
  • write
  • holds to error workflow
ready waiting on a person held or failed

run log · sandbox · made-up records
Architecture

Where the data goes, and where it never goes.

Below: the checks we write into every pipeline, the five places a call's data can sit, and the three keys you hold. Each check is code we write and test for your build.

A

What is custom-built

design · not built yet

The checks run in order. Each one passes the run on or holds it, and a held run writes nothing. Open a check to read what it does and when it holds.

  1. Checks the webhook signature and a five-minute timestamp window before anything is read. Sources: Aircall transcription.created, Dialpad call_transcription, Fathom new-meeting-content-ready, or a paste or upload.

    holds whenA bad or stale signature is refused. Nothing is read.

    timestamp within 300 s and signature valid → read · else refuse
  2. Your team member confirms the recording disclosure was stated and the person on the call agreed. On the made-up call the disclosure is at 00:11 and consent at 00:19.

    holds whenNo confirmation, the run waits.

    disclosure_at and consent_at → continue · else hold
  3. Numbers each line L1 to Ln with its time and speaker. The vendor's raw JSON is dropped here, not kept.

    holds whenNothing holds. The raw payload is discarded.

    L{n} · mm:ss · speaker → keep · raw_json → drop
  4. Stops very short or very long input, and calls that carry speaker labels but no caller lines. Ceilings: 60,000 characters of transcript, 25 MB of audio.

    holds whenUnder 150 or over 9,000 words, or no caller lines when labels exist. No model call.

    150 ≤ words ≤ 9000 · caller_lines > 0 when labels exist
  5. Replaces SSN, date of birth, card, bank, email, phone and home address before the model call. Logs a count per token type, never the value.

    holds whenNothing holds. The model call runs on the redacted text.

    [SSN] [DOB] [CARD] [BANK] [EMAIL] [PHONE] [ADDRESS] · counts only
  6. Reads the client record and the open matter from your CRM, ATS or practice tool. A phone match on another record stops the run and asks your team member.

    holds whenPOSSIBLE_DUPLICATE. The run stops and asks your team member.

    phone_match(other_record) → ask "Same person?"
  7. Checks afterclerk.extraction.v1 for types, enums, required keys and no extra keys. Then each quote must sit inside its cited line, case-folded and whitespace-normalized, at 25 words or fewer.

    holds whenOne retry with the error text, then hold.

    required and enums and no extra keys · quote ⊆ line(evidence_id) · ≤ 25 words
  8. Summary at most five bullets, about 120 words. Follow-up at most 180 words. Follow-up document at most 350 words.

    holds whenA draft over its cap fails the draft check.

    bullets ≤ 5 · follow_up.words ≤ 180 · document.words ≤ 350
  9. Whole words, case-insensitive, with * for a stem. Covers evaluative, protected and injected phrasing. Runs on every model draft and every human edit.

    holds whenA match in a model draft holds it. A match in a human edit is a warning only.

    shortlist · pregnan* · ignore previous → hold (model) · warn (edit)
  10. Every name in a draft must appear in the transcript, the system-of-record entry, the matter context or the approver's form.

    holds whenA name that cannot be traced fails the draft check.

    name ∈ transcript ∪ record ∪ matter ∪ form
  11. The approver types their name. Each decision is attributed to that name, and an edit is diffed against version 1 and checked again.

    holds whenEach decision is recorded under a typed name.

    approved_by = typed_name · diff(v1, edit) → re-check
  12. Writes the note to your system of record, the agreed fields and one task. Saves the follow-up email and the follow-up document as mailbox drafts, unsent. Never a stage, a status or a pipeline.

    holds whenNo write without a decision row for that output.

    write ⊆ {note, agreed_fields, task} · mail = draft · decision.approved
  13. Keeps the workflow name, node name, execution id, HTTP status and error class. Drops messages and bodies, so no client text reaches the error log.

    holds whenThe run stops and writes nothing. The error log keeps IDs only.

    keep: workflow, node, execution_id, http_status, error_class · drop: message, body
  14. Holds the drafts and the transcript in staging until the decision. Deletes transcript and audio within 24 hours of it, a logged manual step until automated. Purges logs at 30 days and reports the counts.

    holds whenNothing reaches a system before approval. The sweep alerts if it deletes nothing for three days while open calls exist.

    ttl = 24 h from decision · logs ttl = 30 d · alert if deleted = 0 for 3 d and open_calls > 0
B

The data map

made-up records · sandbox

Five places a call's data can sit. Pick one to see what it holds, for how long, and who can revoke it. Move through the run to see what each place still holds. Never: a client or anyone else receives anything without a named person's approval.

five territories · one runmade-up records · sample
  1. 1 Transcript in, at intake.
  2. 2 Redacted request out. Drafts back.
  3. 3 After approval: note, fields and task to your system of record. Drafts to the mailbox, unsent.
  4. 4 Transcript and audio deleted. Logs purged at 30 days.
time through the run

C

Revoke in one step

made-up records · sandbox

One switch per key you hold. Flip one and the pipeline stops at once. These switches change this page only; nothing is sent to any system.

  • System-of-record access key

    Reads the client records the run needs. Creates notes and tasks. Updates the fields you agree.

    revoke in your system’s admin console
  • Mailbox grant

    Saves drafts in your Gmail or Outlook. Sends nothing.

    revoke in your Google or Microsoft account
  • Hosting account access

    Runs the workflow in your hosting account. Switching it off stops new intake. Nothing breaks in your system of record.

    switch the workflow off in your hosting account

Security

What we touch, and what we never touch

The architecture above shows every step. Here is the short version a security reviewer asks for: we read the call and the two records the run needs, through keys you create; identifiers are removed before the model sees the text; nothing reaches your system of record, a client or anyone else until a named person at your firm approves; every decision is logged with who, when and what changed. We do not record calls.

What we need from you: an access key with the narrowest permissions (read the client records the run needs, create notes and tasks, update the agreed fields), three to five sample calls or documents, and two of your team for the acceptance test.

sample log · made-up records · sandbox

We never touch the stage, the status, the pipeline or any record the approval did not name.

register · 6 entrieswhat we do, and how you check it

Showing 6 of 6 entries

  • Access

    Who can send anything to a client or anyone else?

    Only your team. Nothing is sent or written until a named person approves it.

  • Model

    Does the model train on our clients' data?

    No. The model provider's commercial terms say it may not train models on customer content sent through the API, and the key is in your name.

  • Keys

    Whose accounts and keys?

    Yours: your hosting account, the model provider and the transcription provider. Each client has separate credentials in a secrets manager, never shared between firms.

  • Model

    What does the model see?

    The transcript, the record context and your template, with identifiers removed first.

  • Retention

    How long do you keep call data?

    Transcripts and audio are deleted within 24 hours of the approver's decision. That deletion is a logged manual step until the automatic job is built. Workflow logs are kept 30 days.

  • Breach

    When do you tell us about a breach?

    Within 48 hours of awareness, in writing, with what was affected and what we did.

You can do these without asking us

  1. Revoke the access key in your system of record, mailbox and hosting account, one step each.
  2. Export the workflow, prompts and logs from your own hosting account.
  3. Switch the workflow off. Nothing breaks in your system of record.
  4. Request deletion of anything we hold. We confirm it in writing within 30 days.
  5. Ask for the sub-processor list and the data processing addendum before we start.

Book a call with your security questions

Administrative by design

How it stays administrative

The workflow writes up the paperwork. It never scores, ranks, screens or decides about a person.

What it will do

  • Extract the facts the person on the call stated, each with the sentence it came from.
  • Draft the note, summary, follow-up document, follow-up email and task for a named person at your firm to approve, edit or reject.
  • Record every approval, with who, when and what changed.
  • Record figures and dates exactly as the person on the call states them.
  • Stop and ask when a record may be a duplicate or a fact is missing.

What it will not do

  • Score, rank, rate, label or classify a person, or judge whether they qualify for anything.
  • Screen, filter, shortlist or reject a person.
  • Move a record between stages or change a status.
  • Send anything to a client without a named person's approval.
  • Ask for, extract or store anything the call did not need.

The design rule is simple: it never scores, ranks, screens or decides about a person. It writes up the paperwork and a named person at your firm decides. This is a design position, not legal advice. We walk your counsel through it.

Recording consent, state by state

design view · not legal advice 11 all-party · 3 situational
  • All-party consent (11)
  • Situational (3)
  • Not on either list
  • ←→↑↓ move · Enter pin · Esc clear
-- Hover, focus or tap a state No state selected A state shows its status here. Click or press Enter to pin it.

Recording consent applies to every sector that records calls. The recording announcement is yours; your counsel decides the wording. Anyone who declines goes through the paste-in route. Source for the state list: Rev, November 2025.

Free build audit

Book 30 minutes. Leave with a plan.

Pick a time on the right. Bring your IT or compliance person; it’s the same 30 minutes.

  • 30 minutes on Zoom or Google Meet
  • An honest answer on whether a build is worth it for you
  • A written scope and fixed quote afterwards, free
  • No pitch deck, no follow-up sequence

Rather email? neo@afterclerk.com

Loading the calendar…Open the calendar