Truthring
For procurement and risk · vendor evaluation

The two answers that disqualify us, before the ones that sell us

We hold no SOC 2 report and no ISO 27001 certificate, and our quantitative accuracy results are still forthcoming. If either is a gate in your process, you have the answer in thirty seconds rather than in week six of a questionnaire.


Why the disqualifiers come first

A buyer who finds a missing certification in week six has spent six weeks and now has to explain why the shortlist was wrong. What we offer in place of certificates is specificity: every answer below is what is true today, and where something is undecided it says so in those words rather than in the future tense vendors use to make an absence sound like a roadmap.


Who you would be contracting with

Truthring is a product of Lacewing Technologies, an independent software company in Navi Mumbai, Maharashtra, India. It is a sole proprietorship: Dipak Ashok Bhosale. Contracts are governed by Indian law, Maharashtra jurisdiction. Lacewing also operates TextSight.ai, an AI text detection and writing suite founded in 2025.

Your third-party risk function will read that as concentration and key-person risk, correctly. A small proprietorship has no audited financials for your onboarding pack, limited depth behind the engineering, and no acquirer standing behind continuity; the usual mitigations are undefined. [VERIFY: decide and publish the position on source escrow, business continuity and exit assistance, plus the entity registration details to be named in contracts] Raise jurisdiction early if you are buying from the EU or UK: the transfer mechanism is a privacy-office question that arrives before any security question. Compliance has the current position.


Data handling, in the order a questionnaire asks

What we receive

An audio file and whatever metadata your integration attaches. We do not transcribe, so the words spoken are never extracted. Voice is biometric data in several regimes; the upload is a processing decision, not an IT decision.

What we keep

Audio will be deleted after analysis [VERIFY: retention not yet set]. A one-way hash is retained so a report can be tied back to the exact file. Retention windows and backup lifetimes sit on data retention.

Where it runs

Hosting region, sub-processors and backup locations are the three answers most packs need in writing. [VERIFY: publish hosting region, full sub-processor list with purposes, and backup locations]

Paper you can sign

A data processing agreement, standard contractual clauses where they apply, and a security schedule. [VERIFY: DPA, SCC position and security schedule not yet finalised]

One point is easy to miss in a security review and expensive to miss in a privacy review. Analysing an archive of calls is a different processing activity from analysing the calls in dispute, because the first sweeps every customer and employee who complained about nothing. Whoever signs off should know which they are approving.


Deployment, integration and what comes back

The product is a hosted service reached over an API: submit a file, receive an analysis. There is no live-call path and no inline decision, which rules out contact-centre screening. On-premise, private-cloud and air-gapped builds are the three deployment questions regulated buyers ask most, and none exist today. [VERIFY: state whether a self-hosted or VPC deployment will be offered, and on what terms]

An analysis returns a verdict state, a confidence, the generator family where a signature matches one we hold, the audio conditions that capped the result, and a reference code. The three-state output matters for integration design: unclear is a real result, not an error, and a system that maps it onto either of the other two has invented a decision your process never made. Route unclear to a person, not a default.

For an audit trail, use the verified report: file hash, timestamp, engine version, applicable limitations, permanent URL. That keeps a decision reviewable eighteen months later, so store the reference code rather than the score alone. Retraining also means a clip scored today may score differently later; the changelog records movements including the ones that made a rate worse. If your control needs a stable result, raise it as a design constraint now.


Support, and the fields vendors usually invent

There is no published service level agreement, no committed response time, no uptime history, no support tier and no 24-hour desk. Filling those fields with plausible numbers is the easiest lie in enterprise software and the one most likely to surface during your first real incident, so they are empty. [VERIFY: SLA, support hours, incident response commitments and uptime reporting not yet defined] There are no reference customers, logos or case studies either: the product is pre-launch. Access is by request. [VERIFY: pricing, contract terms and access process for organisational buyers]


When somebody challenges a result

Plan this before deployment, because it is the part that gets improvised badly. The challenge comes from an employee, a customer or a lawyer, and it says the same thing every time: your system called my recording fake and I cannot disprove it.

Four things make that survivable. The reference code lets the challenger pull the same report you acted on, moving the argument onto the audio rather than onto whether you checked properly. The engine version lets a re-analysis be compared like for like. The stated audio conditions show whether the clip was ever good enough to carry a strong conclusion, and on compressed telephone material it often is not. A named decision-maker can explain what weighed on the outcome besides the score. Write the escalation path in alongside the tool: who re-runs it, who reviews it, what the challenged person may see, and what happens to the original decision meanwhile.


What this cannot do for your organisation

It cannot satisfy a control that requires certification. No SOC 2, no ISO 27001, no third-party penetration test report. [VERIFY: independent penetration test not yet commissioned] If your framework needs one to accept a vendor, technical merit does not substitute.

It cannot prevent anything. No real-time interception, no blocking, no agent prompt, no alert while a call is live. It analyses recordings after the event.

It cannot identify a speaker. No speaker comparison, no voiceprint matching. Whether a voice belongs to a particular person is a different category with a different failure profile.

It cannot supply a figure for your risk register yet. Accuracy and false positive rates are forthcoming. A paper needing a quantified error rate should wait for measured numbers rather than borrow one from a competitor’s marketing.

It cannot be the reason a person is sanctioned. Dismissal, refusal, exclusion or referral on the strength of a verdict is the failure mode that does real damage, because the accused has no evidence available that answers the accusation. A named human decides, weighs the rest of the file, and explains it to a regulator without the phrase “the system flagged it”.


Questions from procurement and risk

Can you complete our security questionnaire?

Yes, and several answers will be “not yet” rather than a number. Where a control is not implemented we say so instead of describing an intention in the present tense, which is why questionnaires get re-opened later. Start from the security page and send what it does not cover.

Is our audio used to train your models?

Audio will be deleted after analysis [VERIFY: retention not yet set]. Any training use would require an explicit opt-in in the contract rather than a clause buried in terms. [VERIFY: confirm the training-data position in contract language]

What happens to our data if the company stops trading?

A fair question for a sole proprietorship, and one we cannot answer with a signed continuity plan today. Because audio will be deleted after analysis the exposure is mostly reports and account records, but exit assistance, data return and escrow terms are undefined and should be negotiated rather than assumed.

Who signs off that a result is fit to act on?

You do. The report states what was found, at what confidence, under which conditions and on which engine version. Turning that into action against a person, a claim or a payment is a decision your policy allocates to a named role, with an escalation path for challenges.


Read the constraints before the capabilities

Obligations around biometric data, automated decision-making and cross-border transfer differ by jurisdiction and are moving. Nothing here is legal advice; take your own in each market you operate in.

Reviewed