For IT, privacy and compliance reviewers

The details you'll want to check.

A straightforward account of what AskLight collects, where it goes, how long it's kept and what we haven't finished yet.

For it & privacy

What AskLight does for you.

Paused by default

Devices listen only after a resident presses the button; pause or remote disable clears unsent audio.

Audio deleted after processing

Short clips are stored privately, processed, then deleted; a cleanup sweep and storage lifecycle act as backstops.

Encrypted in transit

Devices, apps and browsers connect over TLS; devices validate the server.

Device credentials

One-time, expiring enrollment codes; per-device tokens stored only as hashes; revoke at any time.

Organisation isolation

Every query is scoped to the organisation and the user's units; isolation is covered by automated tests.

Network needs

Devices need Wi-Fi with outbound HTTPS. No inbound ports; no computer in the room.

Questions

Do you hold certifications such as SOC 2?

Not yet. We'd rather say so than imply otherwise. Our trust pages describe the controls that are in place today and known limitations.

Who processes the audio?

Clips are processed by a Google Gemini model through Google's paid developer API. AskLight runs on Cloudflare infrastructure.

Where is data stored?

On Cloudflare's managed services. Region-specific hosting is not offered yet; ask us if your organisation has residency requirements.

See AskLight on one of your units.

Tell us about your nursing home. We'll walk through how a pilot works and whether AskLight is a fit — no commitment.