Security and data handling

Voice is intimate. We treat it that way.

A voice is closer to a fingerprint than a font choice. The way audio is stored, who can access it, and how consent is captured for a cloned voice all sit at the centre of how Koythu is built - not at the edge.

Principles that came first, not after

Voice cloning requires real consent, always. No scraped datasets, no proxy submissions, no override for a big enough customer.

Content submitted to Koythu is never used to train the underlying models. Fine tuning happens on data we own or licence explicitly.

Retention is measured in days by default, not years. If you need longer retention for a project, you turn it on - it is not the default.

Compliance posture, stated honestly

SOC 2 Type I audit in progress. Type II readiness assessment complete, observation window underway.

GDPR data processing terms available on request for European customers. DPA covering both controller and processor scenarios.

India IT Rules 2011 and the Digital Personal Data Protection Act 2023 obligations tracked and applied. Named grievance officer reachable through the Contact page.

This page states current status only. Any certification listed is either live or in an audit window we can name - nothing here is forward looking marketing copy.

Data handling

What is stored, for how long, and who can see it.

What is stored

Scripts you submit, the audio the studio renders, and consent records for cloned voices. Nothing about a session is kept beyond what a session needs.

How long

Rendered audio is retained for 30 days by default, extendable per project. Scripts submitted through the studio expire in 24 hours unless you pin them to a project.

Who can see it

Only you, the members of your workspace you invite, and a narrow set of Koythu staff bound by contract who need access to run the service or respond to a support request.

What we never sell

Scripts, generated audio, or cloned voice profiles. There is no training pipeline that quietly reads what you submit - your content stays yours.

Encryption

Standard, boring, done properly. The way encryption should be.

In transit

Every request to the API and every studio session runs over TLS 1.2 or higher, with modern cipher suites only. HTTP is redirected, never accepted.

At rest

Audio files, consent records and voice profiles are encrypted at rest with per project keys. Backups follow the same encryption model.

Tokens

API tokens are scoped to voices, languages and usage caps. They can be rotated without downtime and are hashed at rest.

Voice cloning consent

The one place we never bend.

Reporting

Found something we should know about? Tell us directly.

Security reports, responsible disclosure requests, and voice misuse complaints all reach the same team.

Reach the security desk at security@koythu.com. Grievance officer inquiries are routed through the Contact page.