prepared for Cartesia · prepared privately · illustrative only · not affiliated with Cartesia · not indexed

On 2 August 2026, synthetic audio in the EU must carry a machine-readable mark. Your docs never use the word watermark.

EU AI Act Article 50(2) applies on 2 August 2026. Providers of AI systems that generate synthetic audio must mark the outputs in a machine-readable format, detectable as artificially generated (Article 50 text). Cartesia already runs a dedicated EU endpoint, one of five regions (data residency docs). That endpoint serves exactly the population the article protects.

Hive comes alongside the engine as a sidecar. At the moment of each generation it makes an independent, signed origin receipt that anyone can check offline. It never synthesises audio, never clones a voice, never gates a request, and never sits in the inference path. It does not judge. The receipt proves what was generated, under which policy, on whose attestation. It does not decide legality and does not guarantee compliance. Signing costs 0.098 ms (p50), which is roughly a thousandth of the sub-90ms latency budget Sonic 3.5 targets (TTS API reference).

Non-customer notice. This page is illustrative and was prepared privately by Hive Civilization Inc. It is not affiliated with, sponsored by, or endorsed by Cartesia AI, Inc. It does not state or imply that Cartesia is a customer, partner, pilot, or endorser, or that Cartesia uses Hive. Nothing here is a legal opinion. Every fact is sourced inline and should be re-verified before external use.
2 August 2026
Article 50(2) transparency obligations apply from 2 August 2026, with relief to 2 December 2026 only for systems already on the market. Penalties reach €15 million or 3% of total worldwide annual turnover.
Voice is in scope
The Commission's final Article 50 guidelines, adopted 20 July 2026, confirm that voice falls inside the marking obligation. The question is no longer whether audio counts.
813,326 bytes · zero hits
The complete published documentation corpus, 813,326 bytes, contains zero occurrences of "watermark" and zero occurrences of "C2PA". No detection tool, no verification endpoint, no content credentials.
The distinction this page rests on
Cartesia's compliance posture is real and better than most of the category. Certifications attest to process. None of them produce an artifact a third party can check about a specific piece of generated audio. That gap is the only thing on offer here.
Concept observation by Hive
credit where it is due · stated first, not last

What Cartesia already has

This section comes first on purpose. A pitch that pretends the gap is negligence is a pitch that has not read the trust centre. Cartesia has done the compliance work that most voice providers have not, including an attestation that is genuinely unusual for a model vendor.

Held today · verified against the public record
ArtifactStatusDetailSource
SOC 2 Type IIheldAttested.trust.cartesia.ai
PCI DSS 4.0.1heldAttested as a service provider. Unusual for a voice vendor.trust.cartesia.ai
HIPAAheldCompliant, with BAAs available.cartesia.ai/security
GDPRheldDeclared 24 September 2025, with a published DPA.cartesia.ai/dpa
Trust centreheldLive, public, self-serve.trust.cartesia.ai
Data residencyheldFive regions, including a dedicated EU endpoint.data residency docs

Swipe the table sideways for the source links ›

Not held today · absent from the trust centre
ArtifactStatusBasis
ISO 27001not heldAbsent from the public trust centre.
ISO 42001not heldAbsent from the public trust centre.
FedRAMPnot heldAbsent from the public trust centre.
AIUC-1not heldAbsent from the public trust centre.
● what a certification does

It attests to process

SOC 2 Type II says controls were designed and operating over a period. PCI DSS says a cardholder-data environment met a standard. HIPAA and a published DPA say the contractual and administrative apparatus exists. All of that is real work and none of it is in question here.

● what it does not do

It says nothing about one clip

No certificate in the table above produces an artifact a third party can check about a specific piece of generated audio. A rights-holder holding one 20-second clip cannot read a SOC 2 report and learn when that clip was made, under which policy version, or on whose attestation of consent.

● the whole pitch, in one line

Process proof, then artifact proof

The argument on this page is not that Cartesia is careless. It is that process proof and per-output proof are different objects, and only one of them can be handed to a regulator, a rights-holder, or an enterprise customer's counsel without access to Cartesia's systems.

Context, for scale rather than pressure: Cartesia raised $100M announced late October 2025, co-led by Kleiner Perkins and Index Ventures with Lightspeed and NVIDIA participating (Reuters), and describes a reach of 50K companies (Line launch). No valuation has been disclosed and none is stated here.

exposure 1 · article 50(2) · applies 2 august 2026

The statutory deadline is 2 August 2026, and the EU endpoint is already built

Article 50(2) is short, and it asks for an artifact rather than a policy.

Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated. EU AI Act, Article 50(2) · artificialintelligenceact.eu/article/50
Applies 2 August 2026
Relief to 2 December 2026 exists only for systems already placed on the market. Anything shipping into the EU after the date carries the obligation from day one.
€15M or 3% of turnover
Penalties for transparency breaches reach up to €15 million or 3% of total worldwide annual turnover, whichever is higher under the applicable provision.
Guidelines adopted 20 July 2026
The Commission's final Article 50 guidelines confirm voice is in scope. Nine days before the obligation applied, the interpretive question closed.
Zero and zero
The published documentation corpus is 813,326 bytes. Occurrences of "watermark": zero. Occurrences of "C2PA": zero. No detection tool, no verification endpoint, no content credentials are documented anywhere in it.

The EU endpoint sharpens the point rather than softening it. Cartesia has already built regional infrastructure for European customers across US, EU, UK, India, and Australia endpoints (data residency docs). The population served by that endpoint is exactly the population Article 50(2) protects. The regional work is done. The marking artifact is the piece that is missing.

● today

The output is unmarked

A generated clip leaves the API as audio. Downstream, nothing distinguishes it from a recording of a person, and there is no documented endpoint anyone can call to ask.

● with Hive as a sidecar

The output carries a signed receipt

Media Origin Receipt™ is cut per generation, and MoRSo™ carries it alongside the audio. Machine-readable. Verifiable offline by anyone, with no dependency on Cartesia being reachable or willing to confirm.

● what stays with Cartesia

The engine, untouched

No model change, no retraining, no change to the audio itself. The receipt is a separate object. If Hive is unreachable, generation proceeds exactly as it does today. Fail-open by design.

What a receipt cannot decide. A Media Origin Receipt™ is not a Commission-approved marking method, and no regulator has reviewed it. Whether any given marking approach satisfies Article 50(2) is a determination for Cartesia's General Counsel and outside counsel, not for a vendor page. What the receipt does is produce a machine-readable, independently checkable artifact where there is currently none.
exposure 2 · structural observation, not a criticism of the engineering

Zero data retention stops where the risk starts

Cartesia shipped zero data retention for agents plus a Call Redaction API in June 2026 (changelog). It is a real control. The documentation is also explicit about where it stops.

ZDR is not available for voice cloning, PVC, voice creation, and other features that intrinsically require data storage. Cartesia ZDR documentation, verbatim · docs.cartesia.ai/enterprise/zero-data-retention

The strongest privacy control the company offers is unavailable on the single workflow that carries biometric, right-of-publicity, and consent exposure. This is not a criticism of the engineering. A cloned voice must be persisted to be usable. The observation is narrower and harder to answer: the control and the risk do not overlap.

● the carve-out, and two facts next to it

Clone paths run in the cloud

Voice cloning cannot be self-hosted. Enterprise self-hosting exists, but the clone path runs in Cartesia's cloud, which is consistent with the retention carve-out (ZDR docs).

● default direction of travel

Trainable by default, opt-out

Terms §5.3(c) makes self-serve inputs and outputs trainable by default, with opt-out available rather than opt-in (Terms of Service). Enterprise terms differ. The self-serve default is the one that scales fastest.

● the Hive answer

Prove what happened to it

Where data must persist, prove what happened to it. PBS™ for continuous runtime-control proof. Egress Bond™ for semantic-class and volume caps on voice-sample movement. ViewKey™ for role-scoped projections, so an auditor reads the event without receiving the voice. Retention you can prove beats retention you promise.

What a receipt cannot decide. A retention receipt does not make persistence lawful, does not satisfy a data-subject erasure request on its own, and does not establish that a voice sample was collected with a valid basis. It fixes the record of where the sample went, under which caps, and who read a projection of it.
exposure 3 · ten seconds, free, unverified

Ten seconds, free, and nobody checks whose voice it is

Instant cloning takes 10 seconds of audio and is free on every plan, including the free tier (clone-voices docs). An exhaustive read of the cloning docs, the API reference, and the OpenAPI schema finds no identity verification, no spoken verification statement, no voice captcha, and no consent attestation of any kind.

10 seconds · free tier
Instant clone from ten seconds of reference audio, free on all plans. Nothing in the documented flow asks who the voice belongs to.
Pro clone · $49/month
Professional cloning needs 30 minutes of audio, two hours recommended. The only gate is the $49/month Startup plan. Money, not identity.
The AUP is representational
"You may only submit your own voice and audio recordings or those of others with explicit consent." A user asserts it by proceeding. Nothing verifies it.
Terms §4.2(14)
The Terms additionally bar voices of deceased persons and of political candidates. Both bars are text. Neither is checked at the point of cloning.
The Hive answer · a consent receipt cut at creation, not reconstructed later
OriginProof™Human-origin attestation bound into the voice-model creation event, so the assertion that a human submitted a human voice is a signed record rather than a checkbox state in a web form.OriginProof™ · human-origin attestationWhat a receipt cannot decideIt does not establish that the human who attested had the right to that voice.
SPR™Proves the cloning instruction came from an authorised party under a named authority, rather than from any holder of a valid API key.SPR™ · signed party recordWhat a receipt cannot decideIt does not evaluate whether the authority granted was adequate for the jurisdiction.
Physiological Provenance Receipt™Binds reference audio to a live capture rather than a downloaded clip, which is the difference between a consenting speaker and a podcast episode someone found.Physiological Provenance Receipt™ · liveness bindingWhat a receipt cannot decideLiveness is not identity. It narrows the population; it does not name the person.
Refusal Ledger™ at the gateThe deceased-persons and political-candidate bars in Terms §4.2(14) become bounded, checkable policy state at the moment of clone creation, not prose on a page (Terms).Refusal Ledger™ · signed mutation chainWhat a receipt cannot decideIt cannot tell whether a given voice belongs to a political candidate. It records which bar was in force and what was asserted.
What a receipt cannot decide, at the level of the whole exposure. A signed consent receipt does not establish that consent was legally sufficient and does not resolve a rights dispute. It fixes the record of what was attested, by whom, and when. That record is the thing that does not exist today, and the thing every later dispute asks for first.
exposure 4 · the policy exists; the history does not

Your policy is a page, not a proof

The acceptable use policy (AUP) and the deceased-person and political-candidate restrictions in the Terms (Terms of Service) live on web pages. Web pages change without notice and without version history. A customer who needs to demonstrate to their own regulator which policy was in force on a given date has nothing to point at.

● today

Trust the current page

An enterprise customer's counsel can read today's AUP. They cannot prove what it said in March, whether a bar existed then, or when a threshold moved. The vendor's own assertion is the only record.

● with Hive

A signed mutation chain

Refusal Ledger™ puts the refusal and consent policy on a signed mutation chain with bounded zero-knowledge envelope proofs. A rights-holder, auditor, or regulator verifies the policy bounds and when they changed, without seeing the internals.

● two companions

Drift alarms and off-hours keys

Howler™ cuts a signed alarm when a cloning request drifts toward a flagged or public-figure voice. Diurnal Bond™ requires k-of-n approval for off-hours clone creation, so a 3am pipeline cannot mint a voice on one key.

What a receipt cannot decide. A ledgered policy does not make the policy adequate, and a signed alarm is not a finding of misuse. The chain proves which bounds were in force on a date and when they changed. Whether those bounds were the right ones remains a judgment call that stays inside Cartesia.
exposure 5 · litigation precedent · pending unless a court has finally held otherwise

When the claim lands, your own logs are not the evidence

The doctrinal map for voice was drawn in Lehrman v. Lovo, No. 1:24-cv-03770 (S.D.N.Y.). Judge Oetken's opinion of 10 July 2025 let breach of contract, New York right-of-publicity, and New York consumer-protection claims proceed, while dismissing the Lanham Act claims and most copyright claims (Reuters, opinion PDF).

The copyright holding
Copyright does not protect against imitation of a voice, only direct copying of a fixed recording. Vendor exposure runs through state right-of-publicity and contract, not federal IP.
The limitations reasoning
The court rejected a one-year limitations defence, reasoning that a model trained on plaintiffs' voices "was arguably continuing to replicate those voices each time the model generated new clips."
Stayed, May 2026
Lovo filed for bankruptcy and the copyright suit was automatically stayed in May 2026. The doctrine survives the defendant. Lovo appears here only as precedent.
ELVIS Act reaches the tool
Tennessee's ELVIS Act, in force since 1 July 2024, creates liability for distributing "an algorithm, software, tool or other technology, service or device, the primary purpose or function of which is to produce a particular, identifiable individual's photograph, voice or likeness" without authorisation.

Cartesia has never been named in any lawsuit, enforcement action, or public misuse incident. That is a confirmed negative from exhaustive search, and it is the asset worth protecting. A never-sued vendor holding PCI DSS 4.0.1 and SOC 2 Type II (trust centre) has more to lose from a first incident than a vendor already in the news. The point of a receipt is that the record is built before the first claim, not after it.

● Forensic Rail™

Deterministic replay under a credential

Post-incident analysis runs under a threshold-signed consortium credential and is deterministic-replayable by a regulator, a court, an enterprise customer's auditor, or a rights-holder's expert.

● Hive Ledger

Append-only history

An append-only record of the receipts themselves, so the absence of an expected receipt is an evidentiary signal rather than a gap nobody can see.

● ViewKey™

One event, three vantages

A rights-holder, a regulator, and an enterprise customer each read the same event from their own vantage, without a shared database and without granting anyone new access to Cartesia's systems.

What a receipt cannot decide. A replay receipt does not adjudicate a right-of-publicity claim, does not establish authorisation under the ELVIS Act, and does not decide whether a generated voice is "particular and identifiable". It produces a neutral, checkable record of what the system did, which is the record a defendant currently has to assemble from its own logs under deadline pressure. Every matter named above is a pending allegation unless a court has finally found otherwise.
the map · one exposure, its primitives, and the honest boundary on each

Five exposures, each a receipt, each with a stated limit

Every row below names the Hive primitives that apply and then names what the receipt cannot decide. The second line is not a disclaimer bolted on. It is the reason the first line is worth reading. Hive proves conditions, never verdicts.

Exposure 1 · marking synthetic audio · Article 50(2)
Media Origin Receipt™ · MoRSo™A machine-readable signed origin receipt per generation, carried alongside the audio, verifiable offline by anyone with no dependency on Cartesia being reachable or willing to confirm. The obligation applies 2 August 2026 (Commission FAQ).Media Origin Receipt™ · MoRSo™What a receipt cannot decideIt is not a Commission-approved marking method and no regulator has reviewed it. Whether any marking approach satisfies Article 50(2) is a determination Cartesia's General Counsel makes.
OriginProof™ · Hive LedgerOrigin attestation folded into an append-only history, so a specific clip resolves to a specific generation event and a specific policy state rather than to a support-ticket reconstruction.OriginProof™ · Hive LedgerWhat a receipt cannot decideIt cannot mark audio that was generated before the receipts were switched on. It draws a line forward, not backward.
Exposure 2 · retention where ZDR does not reach
PBS™ · Provenance-Bonded SandboxThe clone-training environment runs with its kernel, engine hash, and firmware version on a signed heartbeat chain, so "it ran under the approved configuration" has continuous runtime proof. The ZDR carve-out excludes voice cloning, PVC, and voice creation (ZDR docs).PBS™ · Merkle heartbeat chainWhat a receipt cannot decideA proven configuration is not a lawful basis for storing biometric data.
Egress Bond™ · ViewKey™Semantic-class and volume caps on voice-sample movement, metered and signed, with role-scoped projections so an auditor reads the event without receiving the voice.Egress Bond™ · ViewKey™What a receipt cannot decideA cap breach receipt does not tell you what the recipient did next, only that the boundary was crossed and when.
Exposure 3 · consent at the moment of cloning
OriginProof™ · SPR™Human-origin attestation plus proof that the instruction came from an authorised party, cut when the voice model is created rather than reconstructed later. Today the flow requires no identity verification and no consent attestation (clone-voices docs).OriginProof™ · SPR™What a receipt cannot decideIt does not establish that consent was legally sufficient and does not resolve a rights dispute. It fixes what was attested, by whom, and when.
Physiological Provenance Receipt™Binds the ten seconds of reference audio to a live capture rather than a downloaded clip, which is the single cheapest structural discouragement to non-consensual cloning.Physiological Provenance Receipt™ · liveness bindingWhat a receipt cannot decideLiveness is not identity, and a consenting live speaker may still lack the right to the voice being imitated.
Exposure 4 · policy that a third party can check
Refusal Ledger™The refusal and consent policy on a signed mutation chain with bounded zero-knowledge envelope proofs, so an auditor or regulator verifies the bounds and the change dates without seeing the internals. The AUP is currently a page with no version history (AUP).Refusal Ledger™ · ZK envelope bondWhat a receipt cannot decideIt proves which bounds were in force, not that those bounds were adequate.
Howler™ · Diurnal Bond™A signed alarm when a cloning request drifts toward a flagged or public-figure voice, and k-of-n approval on off-hours clone creation, which is where unattended pipelines do their worst work.Howler™ · Diurnal Bond™ · k-of-n countersignWhat a receipt cannot decideA drift alarm is a signal, not a finding of misuse, and it cannot identify a public figure it has never been shown.
Exposure 5 · evidence when the claim lands
Forensic Rail™ · Hive LedgerThreshold-signed deterministic replay under a consortium credential, over an append-only history, so the record of a disputed generation is not a set of log lines the defendant wrote about itself (Reuters on Lehrman v. Lovo).Forensic Rail™ · Hive LedgerWhat a receipt cannot decideIt does not adjudicate a right-of-publicity or contract claim and does not establish ELVIS Act authorisation.
ViewKey™ · R3Pv™ · MiR™Role-scoped projections of one event for a rights-holder, a regulator, and an enterprise customer. R3Pv™ rolls many receipts into one grouped proof vector that names the weakest link. MiR™ keeps the model-identity record bound to each generation, so which model version produced a clip is a matter of record.ViewKey™ · R3Pv™ · MiR™What a receipt cannot decideA grouped vector triages review. It does not grade the underlying legal question, and it does not rank claims.

Nothing above is forced onto a use it does not fit. Every primitive named is a receipt-making object that sits alongside the engine. None of them synthesise audio, clone a voice, refuse a request, or enter the inference path. Hive does not judge.

the objection, answered with numbers · measured 27 july 2026 · n=40

Signing costs 0.098 ms (p50). Your budget is sub-90ms.

For a company that competes on latency, the first and correct question is what a receipt costs. Sonic 3.5, sonic-3.5-2026-05-04, targets sub-90ms across 42 languages (TTS API reference). Hive signing at 0.098 ms (p50) is roughly a thousandth of that budget. Ink 2, launched 22 May 2026 at around 100ms, sits in the same order of magnitude (Ink 2 launch).

Measured 27 July 2026 · n=40 · stated as p50, never as an upper bound
OperationMeasuredNote
Sign0.098 ms (p50)Roughly a thousandth of the sub-90ms Sonic 3.5 target.
Verify0.136 ms (p50)Offline. No account, no network round-trip, no vendor dependency.
Dual-signed envelope0.678 ms (p50)Hybrid path, both signatures present in one envelope.
ML-DSA-65 signature3,309 bytesPer NIST FIPS 204. Post-quantum, federal standard.
Smoke tests37 of 37 passSame run, 27 July 2026.

Swipe the table sideways for the full notes ›

Stated plainly · deployment status

Production integrations are pilot-ready rather than deployed. The signing and verification path is measured and reproducible. The integration into a live voice pipeline is the thing a proof of concept establishes, and it has not been established at Cartesia or on Cartesia's behalf.

The seven upstream pre-effect controls were filed as USPTO 64/119,279 on 26 July 2026. A filing is a filing. It is not a granted patent, and nothing on this page depends on it.

Stated plainly · the transparency log

The certificate-transparency-style log for receipt publication is designed, not yet serving. Offline verification does not depend on it. Anyone who wants a public inclusion proof today should treat that as roadmap, not as running infrastructure.

Signatures use a hybrid of Ed25519 and ML-DSA-65 (NIST FIPS 204). Verification is free, works offline, and needs no account. Every number in the table above is a p50 from a 40-sample run on 27 July 2026 and should be re-measured on Cartesia's own hardware during a proof of concept. No figure on this page is a service-level commitment.

The keys stay with you

In plain words: Cartesia would hold the pen that signs. Hive never touches model weights, never receives voice samples, never gates a generation, and never holds your keys.

You hold your own signing keys

The private key that stamps a receipt stays on your own hardware. Nobody else can sign in your name. The signature is yours, not Hive's.

Hive stays a non-custodial sidecar

Hive gives you the way to make and check receipts. It does not synthesise audio, clone a voice, refuse a request, or run the platform, does not enter the inference path, and does not move or store reference audio or model weights. Each event is recorded as a one-way fingerprint and a cryptographic commitment, never the underlying voice data. If Hive is unreachable, generation proceeds exactly as it does today.

THE ASK · PICK ONE SURFACE. HIVE RUNS THE POC.

One surface, not a platform migration. The sharpest candidate is the EU endpoint plus Media Origin Receipt™ on a single model route, because the deadline is dated and the endpoint already exists (data residency docs). The second candidate is the clone-creation path plus OriginProof™ and SPR™, because that is where consent exposure concentrates. Hive builds it, measures it on your hardware, and hands you the receipts and the verifier. Nothing changes in the engine. Naming Cartesia does not imply any agreement, and this page does not state or imply that Cartesia is a customer, partner, pilot, or endorser, or that Cartesia uses Hive.

Legal & regulatory Security & trust Platform & inference Enterprise & deal desk

One line to start: [email protected]
Stephen Rotzin, Founder, Hive Civilization Inc (Wyoming) · [email protected]

illustrative and non-endorsement notice

This page is illustrative only. It was prepared privately by Hive Civilization Inc. and is not affiliated with, sponsored by, or endorsed by Cartesia AI, Inc. or any of its affiliates. It does not state or imply that Cartesia is a customer, partner, pilot, or endorser, or that Cartesia uses Hive. No commercial relationship of any kind exists or is claimed.

Every fact about Cartesia on this page is drawn from Cartesia's own public documentation, terms, policies, and trust centre, or from named reporting, and is linked inline at the point of the claim. No valuation is stated because none has been disclosed. Cartesia has never been named in any lawsuit, enforcement action, or public misuse incident, and nothing here suggests otherwise.

A signed receipt proves that something happened and what it recorded. It does not decide legality, does not guarantee compliance with the EU AI Act or any other law, is not a Commission-approved marking method, and does not adjudicate any court matter. Every court matter named on this page is a pending allegation unless a court has finally found otherwise. Benchmarks are p50 measurements from a 40-sample run on 27 July 2026; production integrations are pilot-ready rather than deployed, and the transparency log is designed, not yet serving. Re-verify every cited source before any external use.

Private, illustrative overview, prepared for Cartesia · noindex / nofollow / noarchive / nosnippet · not affiliated with Cartesia AI, Inc.; this page does not state or imply that Cartesia is a customer, partner, pilot, or endorser, and does not imply Cartesia uses Hive · Hive is a sidecar; it does not synthesise audio, clone a voice, refuse a request, or run the platform, does not enter the inference path, and does not move or store reference audio or model weights · a signed record that a generation occurred is not a statement of legality and does not guarantee compliance · no valuation is stated for Cartesia because none has been disclosed · every court matter named is a pending allegation unless a court has finally found otherwise · benchmarks are p50 at n=40, measured 27 July 2026: sign 0.098 ms (p50), verify 0.136 ms (p50), dual-signed envelope 0.678 ms (p50), ML-DSA-65 signature 3,309 bytes per NIST FIPS 204, 37 of 37 smoke tests pass · production integrations are pilot-ready rather than deployed · the transparency log is designed, not yet serving · signatures use a hybrid of Ed25519 and ML-DSA-65 (NIST FIPS 204), a federal standard · verification is free, works offline, and needs no account · sources used in preparing this overview, to be re-verified before external use: EU AI Act Article 50 text (artificialintelligenceact.eu); Article 50 transparency FAQ (European Commission); final Article 50 guidelines adopted 20 July 2026 (Bird & Bird); documentation corpus, 813,326 bytes, zero occurrences of watermark and zero of C2PA (docs.cartesia.ai/llms-full.txt); zero-data-retention carve-out (ZDR docs); data residency, five regions (data residency docs); instant and professional cloning requirements (clone-voices docs); plan gating (pricing); acceptable use policy (AUP); Terms of Service, including §4.2(14) and §5.3(c) (Terms); SOC 2 Type II and PCI DSS 4.0.1 (trust centre); HIPAA and BAAs (security); GDPR and DPA (DPA); Sonic 3.5 latency and languages (TTS API reference); Ink 2 launch (blog); zero data retention and Call Redaction API, June 2026 (changelog); 50K companies and the Line platform (blog); $100M round, investors (Reuters); Lehrman v. Lovo ruling (Reuters, opinion PDF, Skadden); Lovo bankruptcy and stay, May 2026 (case tracker); Tennessee ELVIS Act tool-provider clause (Holland & Knight).