NATTRLYCompanionship Worth Talking About.

Security at Nattrly

You are trusting us with your conversations, your account, and your card. This page explains what we do with all three — openly, and in plain language.

The part we are proudest of

An AI listens to every video session — and it is listening on your side.

From the moment a session starts until it ends, the conversation is checked in real time against nine specific harms. Not a generic profanity filter bolted on at the end. A list we wrote ourselves, for the ways people actually get taken advantage of.

Five of those nine are about money. That is not an accident, and it is the whole reason we did not buy this off a shelf.

Our security program

We are building toward SOC 2 — the standard organizations use to judge whether a vendor can be trusted with their data — with our controls continuously checked by Vanta. We are early in that work, and we would rather say so than imply a certificate we do not hold. Where we actually stand.

Why we wrote our own categories

Off-the-shelf content filters exist, and they are good at what they were built for: catching profanity, slurs, and explicit images on social media. We looked at them carefully and did not use one.

The reason is simple. A filter built for social media is trying to spot a single offensive sentence. The harm we care most about does not arrive in a single sentence. It arrives as someone patient and charming who spends six weeks being genuinely lovely company, and then mentions a problem with their car. Nothing in that conversation is profane. A generic filter sails straight past it.

So we wrote our own list, aimed at the harms that matter on a platform where people build real trust with each other. It runs on a large language model that weighs a conversation in context rather than scanning it for banned words — it understands that warm, teasing, familiar talk between two people who genuinely like each other is normal and good, and it understands the difference between that and a set-up.

Every category below is one we chose, and every one of them can be tightened as we learn more.

The nine categories

The first five are the exploitation categories — the ones a generic filter does not have.

  1. Financial exploitationExploitation

    Requests for money, gift cards, wire transfers, loans, or financial favors — of any size, however casually they are asked for. The quieter forms count too: being asked to cover a bill, to buy something and be paid back later, to send funds by Venmo, Zelle, Cash App or cryptocurrency, to add someone to an account, to change a will or a beneficiary, or to hand over control of anything financial. Money never moves between you and a Trusted Companion. They are paid by Nattrly, so there is no circumstance in which they need a cent from you — and no reason any of it would ever need to stay between the two of you.

  2. Personal-information solicitationExploitation

    Asking for a Social Security number, bank or card details, passwords, or PINs — and any other personal information a conversation has no reason to need: your home address, your date of birth, Medicare or insurance numbers, answers to security questions, or when your home is empty. A Trusted Companion needs none of it in order to talk with you. Nattrly will never ask you for any of it during a session, and if you ever contact our support team, they will only ask you to confirm details we already hold — never to supply new ones.

  3. Scam attemptsExploitation

    Invented emergencies that need money urgently, investment pitches, and charity fraud.

  4. Coercion for financial gainExploitation

    Emotional pressure, guilt, or manufactured obligation applied to get at someone’s money.

  5. Grooming behaviorExploitation

    The slow pattern — building trust and dependency first, in order to exploit it later. This is the one a generic filter never catches, because no single sentence in it sounds wrong.

  6. Sexual harassment

    Unwanted sexual advances, propositions, or explicit content of any kind.

  7. Threats and intimidation

    Direct threats of violence, and the indirect kind too — "it would be a shame if…", "I know where you live."

  8. Slurs and hate speech

    Racial, ethnic, religious, and other slurs, and language used to demean.

  9. Discrimination

    Demeaning treatment based on race, gender, religion, disability, national origin, or age.

Both sides of every conversation are held to this list. A Trusted Companion is checked exactly as a member is — the standard does not bend depending on who is speaking.

How it works, in layers

Two things run at the same time, because they catch different problems.

  • The instant layer. A fixed list of unambiguous terms is matched the moment it is spoken. There is no waiting and no judgment call — the worst language stops a session immediately.
  • The judgment layer. Everything else goes to the classifier, which reads the conversation as a whole. This is the layer that catches the patient, well-mannered approach, and it is also the layer that knows speech-to-text makes mistakes and does not punish anyone for a mis-heard word.

Clear-cut cases act on their own, immediately, without waiting for a member of staff to be available. Borderline ones are written down for a person to read rather than acted on automatically — we would much rather a human judge an ambiguous exchange than have software guess at it.

The classifier also cannot be talked out of its job. Everything said in a call is treated as speech to be assessed, never as instructions to follow, so saying the right words at it does not switch it off.

What happens when it finds something

On a clear violation, all of this happens at once — automatically, in the same moment:

  • The session ends and the video room closes for both people.
  • The exchange is written down as a flag, with the surrounding context, for a person to review.
  • You are made whole. Any session credit returns to your balance, any charge held against your card is released, and any amount already taken is refunded.
  • An urgent support ticket opens by itself, so the matter lands in front of a person rather than waiting for you to chase it.
  • Both accounts are paused pending that review — including the account of the person who did nothing wrong. The platform deliberately does not decide on its own who was at fault; a person does, and you can reply directly on the ticket.

What it does not do

Being proud of this means being straight about its limits, too.

  • It does not record you. There is no video recording and no audio recording of your sessions. The conversation is assessed while the call is live.
  • It is not a transcript service. Your conversations are never used for advertising, never sold, and never handed to anyone else for their own purposes.
  • Staff are not reading along. Text reaches a person only when a flag is raised, and every one of those views is logged.
  • It is not judging your conversation. It has nine things it looks for. It has no opinion on your politics, your health, your family, or anything else you choose to talk about.
  • It covers video sessions. This protection applies to sessions held on the platform.

The SOS button

A button stays on your screen for the whole session. If anything ever feels off, one tap sends a text message to the emergency contacts you chose when you set up your account. You decide who those people are, and you can change them whenever you like.

Both members and Trusted Companions have the button, and both provide their own contacts. Nobody has to explain themselves to use it, and there is no penalty for a tap you did not mean.

Please read this part. The SOS feature is an informational notification tool only. It sends SMS alerts to your pre-designated emergency contacts. It does not contact 911, police, fire, ambulance, or any emergency response service. In any emergency requiring immediate assistance, you must contact 911 or your local emergency services directly. Nattrly is not a substitute for emergency services.

We will never stop building

Three separate companies vet a Trusted Companion before you ever see them.

The usual standard in this industry is one criminal background check. We run three independent stages, each by a different specialist: identity validation, then government ID with face matching, then a full investigation — criminal records in all 50 states and at federal level, open-source and social records, facial recognition, and reverse image search.

All three have to come back clean. No one stage is allowed to cover for another, and nobody becomes a Trusted Companion until every one of them clears.

Who you are talking to

What each of those three stages actually does:

  • Identity validation — confirming the person is who they say they are, and that the identity itself is real and consistent.
  • Document and face check — government ID verification with face analytics, confirming the document is genuine and belongs to the person holding it.
  • Background investigation — a full search including criminal records across all 50 states and at federal level, social and open-source records, facial recognition, and reverse image search.

An application that does not clear all three does not become a Trusted Companion. Verification results move through a formal review process rather than being waved through by whoever happens to be looking.

Your account

Sign-in is handled by Google’s Firebase Authentication rather than by a password system we invented ourselves. You can sign in with Google, Apple, Facebook, or Microsoft, with a code sent to your phone, or with an email address and password.

  • Two-factor sign-in is available, using a code sent to your phone in addition to your password.
  • Members, Trusted Companions, support agents, and administrators use entirely separate areas of the platform. Being signed in to one does not grant a view of any other.
  • A suspended account is stopped at the front door, before any page loads — not hidden behind a button that could be worked around.
  • Sessions move through a fixed sequence of states, so a session cannot be quietly started, ended, or altered out of order.

Your information

  • We never hold your card number. Card details go directly to our payment processors and come back to us only as a token — a reference that lets us charge an agreed amount and nothing else. There is no card number in our systems to steal.
  • Sensitive fields are encrypted where they are stored, using strong, current, authenticated encryption. Government identifiers supplied by Trusted Companions during vetting are encrypted separately again, under their own key.
  • Phone numbers are indexed by a one-way fingerprint rather than in the clear, so an inbound text can be matched to an account without the number sitting in a searchable list.
  • Everything travels encrypted between your device and us, and between our own services.
  • Staff access is recorded. When a member of staff views or changes account information, that access is written to a log with who, what, and when.
  • Records have documented retention periods set per record type — for example, completed session records are retained for seven years and resolved support tickets for three.

You can ask us to delete your account and personal data at any time — see Data Deletion. Our full Privacy Policy covers what we collect and why.

How we run the platform

  • Support agents cannot browse. An agent must search for you by name and then verify your identity against details you provide before any account information opens to them.
  • Support agents can never see government identifiers or vetting documents, and cannot approve or reject a Trusted Companion.
  • Administrative access is tiered. Staff hold the narrowest level that lets them do their job, and each level opens only the sections it needs.
  • Requests to our systems are rate-limited, and our services accept instructions only from our own applications.
  • Errors are captured and reviewed, so failures surface to us rather than sitting silently in front of you.

Independent oversight

Saying you are secure is easy. We would rather be checked.

Our security program runs on Vanta, the compliance platform that continuously tests an organization’s controls against the SOC 2 framework. Rather than a once-a-year tidy-up before an inspection, Vanta watches the things that actually drift — who has access to what, whether encryption is on, whether laptops are locked and patched, whether known-vulnerable software is sitting in our systems — and raises it with us when something slips.

Behind that sit ten formal written policies, covering information security, access control, incident response, change management, business continuity and disaster recovery, vendor management, encryption and key management, acceptable use, risk assessment, and data classification. They are documents we are held to, not decoration.

To be straight with you about where this stands: we are near the beginning. The policies are written and the monitoring is running, but the formal SOC 2 examination is ahead of us, and we do not hold an attestation today. We started this work before a customer asked us to, and we will update this page as it progresses rather than waiting for a certificate to wave.

If you are evaluating Nattrly on behalf of an organization and need detail on where the program has reached, ask us and we will tell you plainly.

Telling us about a problem

If something during a session felt wrong, or you think you have found a weakness in the platform, tell us and we will look at it. We would far rather hear about it early from you than late from someone else.

Email [email protected] or call (888) 925-5855. If you are reporting a technical weakness, please give us a reasonable window to fix it before sharing it publicly.

This page describes protections in place today and is updated when they change. It is a description of how the platform works, not a contract — the Terms of Service and Privacy Policy govern your use of Nattrly.