Trust & Security

How Constant Concepts handles security and compliance across the AI workers, applications, and outreach programs we build and run for clients — spanning AI Workforce, Build & Grow, and the marketing engine that feeds them leads.

Data security

Every system we build runs on infrastructure designed for enterprise-grade protection — not bolted on after the fact.

  • AES-256 encryption at rest and TLS 1.3 in transit for every piece of data our systems handle.
  • AI reasoning is routed through enterprise AI endpoints under zero-data-retention terms — your prompts and outputs are never used to train third-party models.
  • Strict, tested Firestore security rules scope every read and write to the authenticated owner of that data.
  • Deployed on SOC 2-audited Google Cloud infrastructure, with enterprise AI endpoints that carry their own SOC 2 compliance.
  • HIPAA-ready configurations available for deployments that require them — flag it with your project lead up front.

Voice AI compliance

Every AI voice worker we deploy operates under TCPA-conscious calling practices.

  • Calling windows restricted to 8 AM – 9 PM in the prospect's local time zone.
  • Do-Not-Call registry screening before any outbound call is placed.
  • Upfront AI disclosure at the start of a call, wherever state law requires it.
  • Instant transfer to a live team member any time a caller asks for one.

Email outreach compliance

Outbound email programs we run are built CAN-SPAM-compliant from the ground up.

  • A working opt-out link in every message, honored immediately.
  • A physical postal address in every commercial email footer.
  • Outreach sent from secondary sending domains — never a client's primary domain — to protect your core domain's deliverability and reputation.
  • Conservative per-mailbox daily send caps that stay well inside provider trust thresholds.
  • SPF, DKIM, and DMARC alignment on every sending domain.
  • List verification targeting under a 2% bounce rate before any campaign goes out.

Your code is yours

On final payment, you own what we built for you.

  • A perpetual, royalty-free license to your custom application code.
  • We retain only the pre-existing frameworks and internal tooling that power the build — never your business logic or your data.
  • A 30-day post-launch bug-fix warranty on every custom build.
  • Transparent milestone billing: 50% to start, 25% at design approval, 25% before pre-launch.

Read the full terms

Our own marketing

Lead capture on this site is opt-in, and consent to receive marketing is never bundled with unlocking the content you asked for. That's kept clearly distinct from how the outbound campaigns we run for clients above are configured and operated.

Questions about how we handle security or compliance for your project?

Talk to our team