Security & Trust

Built for enterprise procurement.

We treat your prospect data, call recordings, and CRM access the way your security team expects — documented, encrypted, and auditable.

SOC 2 aligned controls

Access reviews, audit logging, and vendor risk policies modeled to SOC 2 Type II criteria. Full report available under NDA.

Encryption everywhere

TLS 1.2+ in transit and AES-256 at rest. Call recordings stored in encrypted, region-locked buckets with short retention.

GDPR & CCPA ready

DPA available on request. Subject access, deletion, and opt-out requests honored within 30 days across every campaign.

Least-privilege access

Caller and ops access scoped per-client. MFA enforced. Quarterly access reviews and immediate offboarding on role change.

Background-checked callers

Every dialer signs an NDA and completes background screening before touching a client list.

Incident response

24-hour disclosure SLA on any data event. Documented runbook, root-cause review, and customer notification within one business day.

Compliance

Outbound that won't put your brand at risk.

TCPA

B2B calls only, consent-based mobile outreach, DNC scrubbing before every dial cycle, full call recording retention for evidence.

GDPR / UK GDPR

Legitimate-interest assessments for EU/UK outreach, opt-out honored immediately, EU-hosted dialers when required.

CCPA / CPRA

Do-not-sell honored, deletion requests processed within 30 days, consumer rights portal forwarded to client DPO.

CAN-SPAM

Identifiable sender, physical address, working unsubscribe in every follow-up email sequence.

PCI

We do not collect or transmit cardholder data. Payment links are issued by clients directly.

ISO 27001 aligned

Information security management practices modeled to ISO 27001 controls. Certification roadmap shareable on request.

Subprocessors: AWS (us-east-1, eu-west-1), HubSpot, Salesforce, Apollo.io, Aircall, Gong. Full list and DPAs available under NDA. This page reflects our current operating practices; it is not a substitute for a signed agreement.

Need our security pack?

We'll send the DPA, subprocessor list, SOC 2 report, and pen-test summary within one business day.

Book a Free Strategy Call