Telenow for BFSI

Voice AI for banks, NBFCs and insurers in India

Financial-services calling in India is not a volume problem, it is a governance problem. Every outbound call has a window it must sit inside, a suppression list it must respect, a consent record someone may ask you to produce, and a recording that has to still exist eighteen months later. Telenow puts those four things in the dial path itself rather than in a policy document — and then speaks to the customer in the language they actually answer in.

Last updated 2026-09-06

What makes a BFSI call different

Most voice-AI platforms treat compliance as configuration you are trusted to get right. In a regulated book that assumption is the risk: one campaign built by someone in a hurry, one number nobody took off the list, one opt-out that lived in a spreadsheet. These four controls sit below the campaign layer, where a mistake made in a campaign cannot reach them. Where each one sits is stated on the card, because “below the campaign layer” and “on every path a call can leave by” are not the same promise and we are only making the first one.

The calling window is not a preference

On the two paths that dial on a schedule — outbound campaigns, and the follow-ups an agent books itself — calls to +91 numbers are held outside 09:00–21:00 IST by a destination-country floor covering mobile and landline. It intersects with your own campaign window rather than replacing it, so you can be stricter and never looser, and a number that comes up at 21:30 waits for the morning: held, not dropped from the batch. It is a floor under unattended dialling, not a lock on the phone system — an operator dialling one number by hand at 22:00 is not stopped by it, and out-of-hours discipline on manual calls stays a matter of your roster and your policy.

The suppression list is checked at dial time

Your organisation’s Do-Not-Call list is checked at dial time on the paths a collections floor actually calls from: campaigns, follow-ups the agent scheduled itself, an operator clicking call in the softphone or hitting the dial endpoint, and a live transfer out of a call in progress. It is org-wide and always on, so there is no per-campaign switch anyone can forget to tick.

Consent has a record, not a memory

The consent ledger stores who consented, when, from which source, and against which disclosure text and version. Revocation writes a suppression entry in the same database transaction, so there is no window between “they withdrew” and “we stopped calling”. Enforcement is a per-organisation switch with a coverage report, so you can measure the blast radius before you turn it on.

Every call is evidence

Recordings are stored with AES-256 server-side encryption on a retention window you set per organisation, alongside the transcript and a structured outcome. A legal hold placed on a tenant or on one single call is checked in SQL, so it survives retention expiry and every other deletion path.

Where it earns its place

The work that suits a voice agent is the high-volume, low-judgement half of a financial-services phone book: the calls that are the same conversation a thousand times, where consistency matters more than persuasion. The other half still belongs to your team, and the agent’s job there is to find the right person and hand them a warm transfer with context.

Collections reminders

Pre-due nudges and early-bucket reminders: the amount, the due date, the payment link, and a promise-to-pay captured as structured data instead of a note someone types afterwards.

Loan application follow-up

Applicants who dropped out mid-journey, documents still outstanding, and mandate or e-NACH setup that stalled — chased the same day rather than in next week’s call list.

Policy renewal and lapse prevention

Renewal reminders ahead of the grace-period cliff, premium restated from your own data, and a warm transfer to an advisor the moment the conversation turns into a question about cover.

Servicing and branch overflow

Statement, balance and status questions answered from your knowledge base at any hour, with anything account-specific or contentious routed to a person instead of guessed at.

Verification and confirmation calls

Appointment, disbursal and site-visit confirmations, and outbound checks that only need a yes, a no, or a rescheduled slot written back to your system.

Where we would not use it

Settlement negotiation, hardship conversations, disputes and anything that ends in a commitment your customer will hold you to. Those are human calls. The agent gets them to a human faster; it should not be having them.

The controls a security review will ask about

  • All customer data — database, recordings, transcripts and exports — stored in AWS Mumbai (ap-south-1).
  • Provider credentials and API keys sealed with AES-256-GCM envelope encryption; call recordings stored with server-side encryption.
  • TOTP MFA, Google SSO, scoped API keys, per-organisation roles, and tenant isolation enforced at the query layer.
  • Tamper-evident audit trail: mutating API calls are recorded and ranges are periodically sealed into a hash-chained checkpoint, with verification and CSV export. Tamper-evident, not immutable — the point is that later alteration is detectable.
  • Retention configured per organisation for recordings, transcripts, analysis and caller profiles; billing records kept seven years for GST while call content runs on a much shorter clock.
  • Legal hold at tenant or single-call level, enforced in SQL rather than by a background job.
  • Payment card numbers stripped from stored transcripts by default; Aadhaar, SSN and email redaction available on request.
  • Voice cloning gated on a written release naming the subject, with a published destruction schedule for every voiceprint.
  • A named Grievance Officer under India’s DPDP Act with a 72-hour acknowledgement and 30-day resolution commitment, published on our privacy page.
  • Speech recognition and synthesis can run on models we host ourselves, so audio never reaches a third-party voice vendor. The language model on the hosted platform is not ours: it is a vendor you pick, or an OpenAI-compatible endpoint of your own, and the conversation reaches it as text. Only the appliance runs the language model on hardware you control.

Aligned with, never certified against

These are the regimes the product was built against. None of them is a certification, and we will not word them as one: no auditor has issued a report, no regulator has reviewed the platform, and any vendor telling an Indian NBFC that their software carries a regulator’s blessing is describing an obligation that binds you, not them.

India DPDP Act, 2023

A named Grievance Officer, data-principal rights, purpose limitation, configurable retention and India-resident storage. Built for the Act; not an attestation against it.

TRAI DND and TCPA-shaped calling rules

Do-Not-Call suppression enforced org-wide at dial time, destination-country calling-window floors, a consent ledger with proof, and one-touch opt-out recorded mid-call. There is no integration with the national NDNC registry — the list Telenow enforces is yours.

BIPA and biometric law

A voice clone needs a written release naming the subject, and every voiceprint carries a destruction schedule — the earlier of the selected schedule, deletion, or three years since last interaction.

GDPR-shaped data rights

Portable export with a completeness manifest and governed tenant erasure, run by our team on request. A DPA is available; you are the controller and Telenow the processor.

Two ways to run it

On the hosted platform

Data in AWS Mumbai, numbers and carrier compliance handled in-app for Plivo (India business KYC) and Twilio (Regulatory Bundles), and the option to run recognition and synthesis on our own self-hosted models so audio never reaches a third-party voice vendor. The language model here is one you choose — a vendor’s, or your own OpenAI-compatible endpoint — and the transcript of each turn goes to it.

On your own hardware

The same platform ships as a single-tenant GPU appliance: one offline tarball, your SIP trunk into the box, and audio, transcripts, recordings and the language model all staying inside your data centre. It is a design-partner programme today, and the page says exactly what has and has not been verified.

Go deeper

The mechanics behind the four controls above are documented rather than described: Do-Not-Call, outbound campaigns and calling windows, and data protection and the DPA. The named Grievance Officer, the retention commitments and the data-principal rights are on the privacy page, where your compliance team can read them without talking to us first.

Frequently asked questions

Does Telenow satisfy the RBI’s requirements for collections calling?+

No software vendor can answer yes to that, and one who does is selling you something. The Fair Practices Code and the outsourcing directions bind you, the regulated entity — not your telephony stack. What a platform can do is make the obligations you carry enforceable in the dial path, and that is what this one does: a 09:00–21:00 IST floor on +91 numbers dialled by campaigns and by agent-scheduled follow-ups, an org-wide suppression list checked at dial time, a consent ledger whose revocation writes a suppression entry in the same transaction, and a recording of every conversation that a legal hold can freeze. We hold no regulator approval and we do not claim one.

Do you check numbers against the national DND / NDNC registry?+

No. The Do-Not-Call list Telenow enforces is your own: numbers your customers asked to be removed from, numbers your compliance team uploaded, and numbers the agent recorded an opt-out for mid-call. It is enforced org-wide at dial time across campaigns, agent-scheduled follow-ups, manual dials and live transfers. Registry scrubbing against the national list is something you do upstream today. If you need it inside the platform, say so and we will scope it — we would rather quote you for work than pretend it already ships.

Where does our call data live, and who can reach it?+

All customer data — database, call recordings, transcripts and exports — is stored in AWS Mumbai (ap-south-1). Recordings carry AES-256 server-side encryption, retention is set per organisation, and a legal hold on a tenant or a single call is checked in SQL so it survives every deletion path. If storage anywhere we operate is still too far, the same platform ships as an appliance that runs entirely on your own hardware.

Do you hold SOC 2 or ISO 27001?+

We hold no SOC 2, ISO 27001, HIPAA or PCI attestation today, and we will not print a badge before an auditor has written a report. What exists instead is a list of controls you can verify in a technical review: envelope-encrypted credentials, encrypted recordings, MFA and scoped API keys, per-organisation roles with tenant isolation at the query layer, a hash-chained audit trail, configurable retention and legal hold. Tell us your procurement deadline and we will tell you honestly whether we can meet it.

Can the agent take a card payment over the phone?+

We would not route card capture through the agent today. What it does instead is send a payment link over WhatsApp or SMS during the call and confirm the customer has it. That is deliberate: we hold no PCI DSS attestation, and payment card numbers are stripped from stored transcripts by default precisely so card data never lands in your call archive in the first place.

What happens when a customer says “stop calling me”?+

The agent records the opt-out against your suppression list with a link to the recording of the moment it was asked for, and every later dial — campaign, scheduled follow-up, softphone or dial endpoint — is blocked by it. Removing that entry is deliberately awkward: opt-out rows cannot be bulk-deleted, withdrawal is one at a time, it is written to the audit log, and the screen offers to play you the call first. An opt-out should be easy to create and hard to erase.

Do you train models on our calls?+

No. Your conversations, recordings and knowledge bases are used to run your agents and nothing else — they are not used to train models.

How do we prove after the fact that a call went the way we say it did?+

Three artefacts, kept together: the recording, the transcript with a structured outcome, and the audit trail of what was changed in the platform and by whom. Audit ranges are sealed into hash-chained checkpoints, so later alteration of the log is detectable and you can run a verification and export the result. We describe that as tamper-evident rather than immutable, because it detects tampering by anyone who cannot also rewrite the checkpoints — and that distinction is exactly the sort of thing your auditor will ask about.

$1.01 free credit on signup

Try it on your own numbers before you commit to anything

Sign up free and get $1.01 in credit — no card required. Connect your number, pick a template, and go live in minutes.