Data Security & Privacy | AI Sales Training

Training data,
only for the people who need it, within the scope they need.

Sakuraseisai AI Sales Coach does not make conversations, recordings, transcripts, and analysis results uniformly available. Access is controlled according to organisation, role, and sharing settings. This page explains the data-protection principles and verified safeguards relevant to enterprise training.

Last verified: August 7, 2026. Public information is limited to what enterprise customers need for an adoption decision.

Production verification

Key measures verified as of August 7, 2026

We combined design review with permission checks in the production environment and post-change functional verification.

Verified

Organisation sharing starts conservatively

For the organisation reviewed, we confirmed that administrator sharing of transcripts and detailed analysis was disabled.

Verified

Layered access control and least privilege

Access controls are applied at both the application and data-storage layers, together with a least-privilege approach that removes permissions not required for service operation.

Verified

Production checks after changes

After reviewing access permissions, we tested the production environment and confirmed that core functions operated normally within the verified scope.

Managed

No permanent verification access

Temporary verification access used for production checks is removed after verification, and we confirm that unnecessary access paths do not remain.

These checks are internal security verification within the stated scope. They do not represent third-party certification, penetration testing, or certification such as SOC 2 or ISO 27001.

Cloud security design

Core security design for the cloud version

Conversation data used in enterprise training is not made broadly visible simply because someone has administrator status. Multiple access controls are combined in operation.

Organisation-based access

Access managed by organisation

Visible data is separated according to roles such as individual user, learner, and organisation administrator, together with organisation membership. Cross-organisation access is denied by default.

Deny when permission is unclear

Fail closed when permission cannot be verified

If the system cannot verify the data owner, organisation, or viewing permission, access is not granted. Missing information is not guessed; access is denied on the safer side.

Recording restrictions

Recording access is restricted for organisation administrators by default

Recordings are treated as more sensitive than transcripts or evaluation results. Even organisation administrators cannot view other employees’ recordings under the default settings.

Not shared by default

Transcripts and detailed analysis are not shared by default

Conversation transcripts, utterance-level detailed analysis, and evaluation evidence containing conversation content are not shared with organisation administrators unless the organisation confirms the need and explicitly enables sharing.

Disclosure before training starts

Explain data sharing before organisation training begins

Before an organisation roleplay session starts, users are shown the scope in which conversation data and analysis results may be shared with the organisation. Organisation calls are not started before this confirmation.

Field-level visibility

Field-level control of analysis results

Analysis results show only the information required for the user’s role and sharing settings. Information used internally by the service is not automatically exposed to users.

Deployment options

Software version and dedicated hardware

Choose between a software version that uses the convenience of cloud delivery and dedicated hardware that makes it easier to keep data under company control. The choice is based on operating model and data-governance needs, not a simple ranking of which is “more secure.”

Sakuraseisai AI Sales Coach software interface
Software version

Secure operation on a cloud-based platform

We combine multiple safeguards, including authentication, organisation- and role-based access control, least privilege, and protection of data in transit. This balances browser-based convenience with appropriate protection for enterprise training data.

  • Access control
  • Least privilege
  • Protection in transit
Dedicated Sakuraseisai AI Sales Coach hardware used under company control
Dedicated hardware

Store and use data under company control

A dedicated configuration can be designed to store recordings, transcripts, and analysis results in an environment controlled by the company. External communications can be reduced, while storage location, access, retention, and internal use can be managed according to the company’s own policies.

  • Stored under company control
  • Minimise external communications
  • Use as company-controlled data

Network isolation for dedicated configurations

Depending on requirements, we can support configurations isolated from external networks. The actual isolation scope depends on implementation conditions such as AI processing method, updates, maintenance, and backups, so details are confirmed before deployment.

AI data-use policy

We limit the purposes for which customer data is used

Sakuraseisai Co., Ltd. does not currently operate a mechanism that trains its own general-purpose AI models on customer conversation data, transcripts, or analysis results.

External services may be used for processing required to provide the service, such as conversation analysis and improvement suggestions. In those cases, our basic policy is to handle data only to the extent necessary for the function and to limit the purpose of use.

Data retention

Voice-side retention and application-side storage are managed separately

“Voice data is deleted after 30 days” does not mean that transcripts and analysis results are also deleted after 30 days.

Voice processing

Voice side: retention configured for up to 30 days

For production voice processing, call-related data is operated with a retention setting of up to 30 days.

This retention period applies to data on the voice-processing side and is managed separately from the storage period for application-side data such as transcripts and analysis results.

Application database

Application side: transcripts and analysis results may be stored separately

After a roleplay session, transcripts, analysis results, and reference information for recordings may be stored in the application database.

Retention periods for transcripts, analysis results, and similar data are managed according to data type, purpose of use, contract terms, and operational requirements.

Enterprise deployment review

Security review materials are available for organisations considering deployment

If review by information systems, legal, privacy, or procurement teams is required, we can share more detailed materials individually than what is published on this page.

  • Data Privacy & Security Controls Verification Report
  • Security Architecture & Data Flow Overview
  • Data Retention & Deletion Policy
  • AI & Data Handling Review Materials
  • Access Control & Tenant Isolation Verification Materials
Request enterprise review materials

FAQ

Frequently asked questions about data security

Can organisation administrators freely listen to employee recordings?

Under the default settings, even organisation administrators cannot view other employees’ recordings. Recordings, transcripts, and detailed analysis are handled separately because they have different sensitivity levels.

Are transcripts and detailed analysis shared with the company from the start?

Sharing is disabled by default. Only the scope explicitly configured after the organisation confirms the need is shared. Users are also informed of the sharing scope before organisation training begins.

Are all voice data and transcripts deleted after 30 days?

Call-related data on the voice-processing side is configured for retention of up to 30 days, but transcripts and analysis results may be managed separately. This does not mean that all conversation-related data is uniformly deleted after 30 days.

Does Sakuraseisai train its own AI on enterprise conversation data?

Sakuraseisai does not currently operate a mechanism that trains its own general-purpose AI models using customer conversation data. External processing required to provide the service is managed according to contract terms and purpose of use.

Do you have materials for an enterprise information-systems team?

Yes. We have review materials for organisations considering deployment that cover data flows, retention, AI data handling, access control, and related topics. Please contact us if you need them.

Bring security review into the deployment discussion from the start.

We can organise the questions your information-systems, legal, privacy, and procurement teams need to review—including internal sharing scope, data use, retention, and access control—according to your deployment requirements.