TROVA captures in-home sales conversations. We treat that audio like the legal record it is — encrypted in transit and at rest, retained per your policy, two-party-consent workflows in every state that requires them.
No vendor wants to be the one that blocks your IT review. Here's our exact compliance posture and timeline — public and updated as milestones land.
Need our security questionnaire, SOC 2 progress letter, or a custom DPA for procurement? Email security@hellotrova.com — we'll respond within one business day.
The TROVA workflow includes an automated pre-call consent step in all two-party-consent states: California, Florida, Massachusetts, Washington, Illinois, New Hampshire, Montana, Pennsylvania, Maryland, Connecticut. Recording cannot start until the technician verbally confirms the customer's consent.
In one-party-consent states, TROVA captures audio with technician consent by default. Customers can be informed at the discretion of your shop's policy.
For multi-state operators: TROVA detects the customer's address state and applies the appropriate consent workflow automatically.
TROVA is pursuing SOC 2 Type I (target: Q3 2026) and SOC 2 Type II (target: Q1 2027), with continuous controls monitoring through Vanta. While we're pre-attestation, we can share:
Many enterprise IT teams accept pre-attestation vendors with a defined Type I target date. We'll work with yours.
The third parties that touch your data (audio storage, transcription, AI inference, email delivery) are listed publicly and updated when they change: /subprocessors/
30-day advance notice on any subprocessor change, via the email address you signed up with.
TROVA maintains an incident-response runbook with named on-call rotation. In the event of a security incident affecting customer data, we notify affected customers within 72 hours with: what happened, what data was affected, what we've done, and what we recommend you do.
Annual third-party penetration test. Most recent report available under NDA on request.
Security, privacy, or compliance questions: security@hellotrova.com
Looking for our Data Processing Agreement (DPA), Mutual NDA, or AI usage policy? Same address.
Bring your IT lead. We'll walk through encryption, retention, two-party-consent automation, the Vanta dashboard, and the SOC 2 timeline. We've got nothing to hide.