RMT Engineering Logo
For security, risk and compliance

The controls before the capability

Tenant isolation enforced in the database rather than in application code. Recordings encrypted with keys you hold. An audit log you can prove wasn't altered. Answer the questionnaire from the product.

  • 16+ regional compliance packs
  • Encryption keys you hold
  • Hosted in the region you choose
We reply within one business day. No newsletter.

Illustrative interface. Request identifiers, counts and states are sample data, not a performance claim. The screen shows an OptiML governance view: a completed erasure request with its scope and the number of recordings destroyed and transcripts redacted, an audit integrity proof verified, guardrail results, an approval gate on refunds, a cost cap, and the tenant's isolation, recording-key and data-residency settings.

Controls, counted

Three numbers you can put straight into a questionnaire, each of them a property of the build itself and not a policy statement about it.

231 tables under PostgreSQL row-level security, so the database refuses another tenant's row whatever the application asks for
300+ granular RBAC permissions, with hierarchical and custom roles and resource-scoped grants
16+ regional compliance packs — GDPR, HIPAA, CCPA, TCPA, PCI-DSS, DPDP, FINRA, EU AI Act and more

What you care about

Nine control areas, and the specific mechanism that satisfies each one. This is the table that answers most of a security questionnaire before the call starts.

Each control area a security and compliance reviewer examines, and what OptiML gives them for it
Control area What OptiML gives you
Tenant isolation PostgreSQL row-level security on 231 tables, fail-closed tenant context
Access control 300+ granular permissions, hierarchical and custom roles, resource-scoped grants, channel allow-lists
Identity SSO across 8+ providers, SAML and OIDC, SCIM provisioning, TOTP MFA
Encryption AES-256-GCM envelope encryption, per-recording keys wrapped by a tenant key in KMS, TLS and mTLS in transit
Audit Immutable log of every mutation, per-tenant integrity proofs, signed exports, SIEM streaming
Data subject rights Erasure with regulator-proof logs, DSAR register, opt-out handling, configurable retention
PII Detection and redaction across transcripts, logs, exports and analytics, with severity scoring
AI-specific risk Guardrails for injection and PII, cost caps, approval gates, full model-call tracing
Residency Regional hosting with per-tenant retention; customer-managed data residency on Enterprise

What changes in your review

  • The security questionnaire is answered from the platform's own control inventory, not from a narrative about roadmap intentions.
  • AI risk has named controls: grounding, injection defence, budget caps, approval gates and tracing. That inventory is what a reviewer gets instead of a paragraph about responsible use.
  • Recordings and transcripts can be provably erased, with an immutable record of the erasure.
  • The residency question gets a product answer. Your tenant is hosted in the region you choose, and on Enterprise your database and recording storage run in your own cloud account, under keys you hold.

Open the trust centre

Under customer-managed data residency the application, AI runtime, media plane and console run in OptiML Cloud, while the database and recording storage run in the customer's own account OptiML Cloud operated by RMT Application & console AI runtime & guardrails Media plane (WebRTC, SIP) Agent Desk & Supervisor Your cloud account or your own datacentre — Enterprise option PostgreSQL database Recording storage Encryption keys you hold The only durable copy of transcripts and recordings lives here. private connection
Customer-managed data residency is an Enterprise option. The platform keeps running in OptiML Cloud and processes data in transit. What persists with RMT is PII-redacted operational telemetry and a bounded message-queue retention window, both enumerated in the DPA.

Enforced, not documented

The difference between a control and a claim is whether something other than good intentions stops the failure. Each of these four is enforced by a system that does not depend on application code behaving.

Isolation in the database

PostgreSQL row-level security on 231 tables with fail-closed tenant context, so a defect in application code cannot leak data across tenants.

Keys you hold

AES-256-GCM envelope encryption, per-recording keys wrapped by a tenant key in KMS, TLS and mTLS in transit.

Audit you can prove

An immutable log of every mutation with per-tenant integrity proofs, signed exports and SIEM streaming, retained 30 days minimum and configurable per tenant.

Residency with a product answer

Regional hosting with per-tenant retention. On Enterprise, customer-managed data residency puts your database and recordings in your own cloud account.

We run it. You choose where the data lives.

There is one product and one place it runs. The option on top of it concerns data location, which is usually what the obligation actually turns on.

How we host it

OptiML Cloud

Multi-tenant SaaS in the region you choose, with tenant isolation enforced by PostgreSQL row-level security on 231 tables. Operated, patched and scaled by RMT, against a 99.9% monthly uptime commitment in the SLA.

Everyone. This is the product.

Enterprise option

Customer-managed data residency

Your database and recording storage in your own cloud account or your own datacentre, privately connected, with encryption keys you hold. The application, AI runtime, media plane and console continue to run in OptiML Cloud.

Regulated buyers whose obligation is about where the data lives.

Dedicated single-tenant hosting is an Enterprise option: an isolated single-tenant instance inside OptiML Cloud, in your chosen region, with its own retention windows and compliance posture and no shared infrastructure. Still operated by RMT. The platform itself always runs in OptiML Cloud. Customer-managed data residency moves your data, not the software. Your account holds the only durable copy of transcripts and recordings; PII-redacted operational telemetry and a bounded message-queue window persist with RMT, and the trust centre names every row.

Where this goes next

The trust centre carries the full control inventory, the sub-processor list and the document request form. The customer story will sit here once a named customer has approved it in writing.

We publish outcome figures only with the customer's written approval, so this slot stays empty until one is signed off. In the meantime the mechanism above is the honest version.

Until thenBring your own scenario and we will run it live

Talk to our team

Certification claims are statements about a third-party auditor's finding, so a badge appears only once the certificate is issued and links to the certificate or the auditor's register. Customer quotes need written approval from the named customer.

The platform underneath

Everything on this page is the OptiML CX Platform configured for Security & Compliance, not a separate product. These are the modules it leans on.

Book a working session

See it handle one of your real conversations

Bring a call recording, a policy document or a WhatsApp thread from your own operation. We ground an agent in it and run it live on the call. What you hear is your own material, not a canned demo.

  • 30 minutes
  • A working agent grounded in your content
  • No slide deck unless you want one

Book a demo

30 minutes, on your own content. No slide deck unless you want one.

or reach us directly

Your details stay private. We never share them.

This website uses cookies.

Cookies are small text files that allow us to create the best browsing experience for you on our site. By continuing to use this website or clicking "Accept & Close", you are agreeing to our use of cookies. To understand how we use cookies or how to manage them, please see our cookies policy.

Ask OptiML

Powered by RMT Engineering