Trust & safety
Automation with a clear path to human follow-up.
Our standard is simple: tell people when AI is answering, ask before recording, collect only what the job needs, and create a callback request when a person needs to follow up.
Effective September 3, 2026 · Applies to the AlloBoss AI founding beta1. Operating principles
The dispatcher identifies itself as an AI assistant. It must not pretend to be a human employee.
Where all-party consent may apply, audio and persistent transcripts stay off until the caller agrees.
AlloBoss does not transfer live calls to a person. A caller can request a callback, and high-risk or low-confidence calls create one automatically.
The call flow asks only for details needed to quote, schedule, dispatch, and support the requested service.
2. Call Recording Standard
Recording laws vary by state and by the locations of every person on a call. Florida requires prior consent from all parties to intercept a wire, oral, or electronic communication. Our safest nationwide default is therefore all-party disclosure and affirmative consent.
- Disclose first. Identify the business, disclose that the caller is speaking with AI, and explain recording and transcription.
- Wait for a clear answer. Do not treat silence or an unrelated response as consent.
- If the caller says yes: store the consent event, then enable the recording and persistent transcript.
- If the caller says no: keep recording off and continue through a supported non-recorded flow, offer a callback, or provide another non-recorded channel.
- If another person joins: repeat the notice and obtain that person’s consent before continuing to record.
For outbound AI or prerecorded voice calls, the business must separately satisfy applicable consent, identification, do-not-call, and opt-out obligations. The inbound dispatcher must not be repurposed for automated outbound marketing without a legal and product review.
3. Callback to a person
AlloBoss does not transfer an active call to a person. Every live account must have business hours, after-hours behavior, and a callback owner. Saying “human,” “representative,” or an equivalent request creates a callback request without requiring the caller to explain why.
Automatic callback triggers
- Two failed attempts to understand a critical detail such as address, date, price, or service type.
- A complaint, refund request, billing dispute, legal threat, discrimination concern, or privacy request.
- A caller who appears distressed, vulnerable, impaired, or unable to provide meaningful consent.
- A safety concern, suspected crime in progress, or any request outside the approved business workflow.
- A quote or commitment above a business-defined limit.
The virtual dispatcher continues the live conversation, collects only the details needed for follow-up, confirms that a callback was requested, and ends the call. It must never claim that a person or technician was reached or promise an exact callback time unless the business has confirmed it.
4. Safety boundaries
- Not emergency dispatch: direct immediate threats to 911 or the appropriate local emergency service.
- No fabricated certainty: do not promise an arrival time, price, availability, or completed dispatch unless confirmed by configured business data.
- No high-impact decisions: do not make final decisions about employment, housing, credit, insurance, healthcare, legal rights, or essential services.
- No unnecessary sensitive data: do not ask for SSNs, bank passwords, complete payment-card details, medical records, or government IDs in routine calls.
- No deceptive identity: the AI identifies itself and may not imitate a real employee or public official.
5. Customer data protection
Our data rule is to collect the minimum needed to complete the service request. Access should be limited to authorized staff of the correct business and vendors required to operate the service.
Call content is not sold or used for targeted advertising. It should not be used to train a shared AI model without separate written agreement. Privacy requests are verified before data is exported, corrected, or deleted.
6. Honest production-readiness status
Policies alone do not make a product secure. Before taking unrestricted paid production traffic, AlloBoss AI must document and test the following controls:
REQUIREDPer-business data isolation and role-based access
REQUIREDEncryption in transit and at rest, with managed secrets
REQUIREDAudit logs for access, changes, exports, and deletion
REQUIREDConfigurable retention, deletion, and account export
REQUIREDVendor inventory, data agreements, and incident-response plan
REQUIREDRecorded consent event and tested no-consent call path
The founding beta does not claim SOC 2, HIPAA, PCI DSS, or ISO certification. Payment-card data should be handled by the payment provider, not by the AI call transcript or AlloBoss database.
7. Official sources
This standard is operational guidance, not a substitute for advice from qualified counsel. Laws may change and may depend on the caller’s and business’s locations.