Trust & Security

Security claims backed by evidence.

Phantone documents the current status of its product, infrastructure, privacy, and operational controls. Controls marked implemented are in place today; controls marked partially implemented or planned are not represented as complete. Phantone is operated by Midtown West LLC.

Last updated: August 13, 2026 · Owner: Matthew Loughran, EMBA — Founder, Midtown West LLC

At a glance

Controls and status

ControlStatusEvidence
Tenant isolationPartially implementedWorkspace-scoped access enforced at the data layer
Encryption at restInherited from providerManaged database and object storage provider defaults
Encryption in transitImplementedHTTPS/TLS across app, API, and webhooks
Role-based access controlPartially implementedDistinct roles stored separately from user profiles
Audit loggingPartially implementedAppend-only event log with export; retention period being finalized
Webhook securityPartially implementedSigned webhook delivery; replay protection and receiver allowlisting in progress
MFA / SSOPlannedEnterprise SSO and MFA on the roadmap ahead of GA
Backups / recoveryInherited from providerManaged database backup and point-in-time recovery
SOC 2 Type 2 (infrastructure)Inherited from providerCloud and managed database provider reports, available under NDA
SOC 2 Type 2 (Phantone product)PlannedPolicies and control matrix being assembled
GDPR / UK GDPRPartially implementedDPA with SCCs available; sub-processor mapping maintained
CCPA / CPRAPartially implementedConsumer-rights intake via compliance@phantone.fm
Independent penetration testPlannedPlanned with a third party ahead of GA
Campaign and impression authenticityImplementedSigned records and transparency-log verification
Signed acoustic payloadImplementedSigned payload with tamper detection at the signal layer
Program detail

How each control actually works

Data protection

Encryption at rest is provided by our managed database and object storage providers; TLS protects data in transit across the app, API, and webhooks. Hosting is in the United States today, and regional hosting options are discussed per contract. Customer data is deleted within the window set in the customer agreement.

Tenant isolation

Workspace-scoped data is isolated at the data layer, with access checks enforced server-side rather than in client code. Isolation coverage is reviewed as new tables and endpoints are added.

Access control

Roles are stored separately from user profiles and checked server-side, so privileges cannot be escalated from the client. Enterprise SSO and enforced MFA are planned ahead of general availability.

Audit logging

Privileged writes — auth events, role changes, campaign mutations, key rotation, and exports — are captured to an append-only log that can be exported. Retention is configurable and set in the customer agreement.

Webhook & integration security

Outbound webhooks are signed with a per-workspace secret so receivers can verify authenticity. Replay protection and receiver-side IP allowlisting are in progress.

Generative AI and customer content

The core signaling, detection, resolution, and impression-recording pipeline does not require customer audio to be sent to a generative-AI provider. Customer audio is not used to train third-party models.

Signal and record authenticity

Acoustic payloads are signed and carry tamper detection at the signal layer. Separately, campaign and impression records are signed and verifiable against a transparency log, so a counted impression can be checked after the fact.

Incident response

We maintain an incident response plan with a 72-hour customer notification commitment for any confirmed Personal Data Breach affecting their data, consistent with our DPA. We target a written postmortem within 10 business days. Contact: security@phantone.fm.

Compliance posture

Infrastructure providers (cloud, managed Postgres) hold their own SOC 2 Type 2 and ISO 27001 certifications; those are inherited, not Phantone's own audit. A Phantone product SOC 2 Type 2 audit is planned. Our practices are aligned with GDPR/UK GDPR and CCPA/CPRA today.

Sub-processors

Who we share data with

Phantone uses a short list of carefully selected sub-processors for cloud hosting, managed Postgres, transactional email, error monitoring, support helpdesk, and payment processing. Each sub-processor is contractually bound to security and privacy obligations equivalent to those in our DPA. We provide customers with 30 days' prior notice before adding a new sub-processor that processes their personal data.

Evidence requests

Request control evidence under NDA

Enterprise evaluators may request the current security overview, architecture summary, sub-processor list, data-flow diagram, incident-response overview, and available control evidence under NDA. We respond to security questionnaires and custom RFIs within five business days, and we will tell you plainly when an artifact does not exist yet.

Compliance team escalation

Question your team didn't see answered?

We respond to security questionnaires (SIG Lite, CAIQ, HECVAT, or your custom RFI) within five business days. No NDA gate to start the conversation.

Midtown West LLC · 705 Gold Lake Dr Suite 250, Folsom CA 95630