Trust & Security

The AI SDR sellers trust — and security signs off on

Conductor pairs its Chrome-based side panel with enterprise guardrails so RevOps, IT, and security leaders can let reps automate mid-meeting without risk.

Transparent execution

  • Pre-execution approvals on every action
  • Immutable audit log with timestamps and actor
  • Exportable traces for compliance reviews

Data residency & control

  • Local-first storage in the Chrome-based side panel
  • Customer-managed API keys by default
  • Scoped encryption keys per workspace

Least-privilege access

  • Role-based controls for SDRs, AEs, admins
  • SSO + SCIM available on Enterprise
  • Granular revocation for skills & connectors
Compliance roadmap
SOC 2 Type II
Audit in flight · Q3 2025

Backed by Vanta with automated evidence collection

GDPR & UK GDPR
Compliant today

DPA + SCCs available, EU data processing on-request

Chrome Web Store policies
Approved

Extension reviewed for permissions + privacy disclosures

Security controls
Encryption

TLS 1.3 in transit · AES-256 at rest · Client-side row level encryption for optional cloud sync.

Secrets

API keys stored in Chrome's encrypted storage. Hardware-backed keychain for macOS + Windows Hello.

Monitoring

24/7 alerting on auth anomalies, model spend spikes, and connector abuse patterns.

Incident response

Runbooks with <30 min paging, customer updates at 1h, retros shared with impacted teams.

Data flow transparency

Every workflow stays local unless you opt into cloud sync. When Conductor calls an AI provider, we show the prompt, model, and spend before it leaves your browser.

Chrome side panel

IndexedDB storage, hardware isolation, zero trust network access for sellers mid-workflow.

Provider calls

Customer-managed API keys, regional endpoints, usage caps per user.

Optional cloud backup

Encrypted session shards, customer-controlled retention toggles.

Skills marketplace

Code-signed bundles, static analysis, manual review for publishing.

Logs & telemetry

Anonymized events for reliability; no prospect data captured.

Access requests

Just-in-time scopes for support, automatically revoked in 24h.

Vendor packet on request

Need a full security briefing? We share architecture diagrams, DPIA templates, and detailed penetration test summaries under NDA.

Vercel
Marketing site + API hosting
USA/EU
Supabase
Optional cloud session storage
USA
Cal.com
Scheduling + calendar handoffs
USA/EU
Linear
Bug tracking + support
USA/EU

Ready for your security review

Loop in security, RevOps, and IT. We bring the documentation, you keep control over every workflow.