Platform · Compliance
Certified where it
counts, evidenced
where you ask.
Banks, insurers, hospitals and carriers audit us against their own regulations. This page lists the frameworks we hold to, what your deployment inherits, and the control that answers each regulation.
- Card numbers are maskedNever written to a transcript
- Read by the taskOnly what the call needs
- Inference runs insideNo prompt leaves it
- Retention is yoursSet by your policy
- Consent checked at dialInside your call windows
- Certified
- Inherited
- Evidenced
What we hold to, what you inherit, what we can show.
A compliance officer needs to know which controls are ours to prove and which are already yours. The runtime runs inside the boundary you already audit, so most of the estate keeps the certificates it holds.
What we hold to
Twelve frameworks, from SOC 2 Type 2 to ISO 42001, with scope.
What you inherit
The runtime runs inside the controls your team already audits.
What we can show
The report behind each one, under NDA, when your review asks.
The inheritance
Most of your estate keeps the certificates it already holds.
Each regulation, one control we can show.
Pick the regulation your auditor asks about. The panel shows the control that answers it and whether the evidence is signed today or supplied on request.
- PCI DSS, taking a card payment
- HIPAA, a patient on the line
- GDPR and CCPA, a data request
- TCPA, outbound calling
RiskPCI DSS, taking a card payment
Card numbers pass through a masked flow and are never written to a transcript.
How it is enforced
The card step runs in a masked flow, so the digits never reach the model, and the transcript records the outcome only.
EvidencePCI DSS
RiskPCI DSS, taking a card payment
Card numbers pass through a masked flow and are never written to a transcript.
How it is enforced
The card step runs in a masked flow, so the digits never reach the model, and the transcript records the outcome only.
EvidencePCI DSS
RiskHIPAA, a patient on the line
Only the health detail a task needs is used, and patient data is not retained.
How it is enforced
Retrieval is filtered by the caller's permissions, so an agent sees the record a task needs and nothing beside it.
EvidenceHIPAA
RiskGDPR and CCPA, a data request
Retention settings and export answer a caller's request to see or erase their data.
How it is enforced
Retention and erasure are settings on your own store, so a subject request is answered from records you hold.
EvidenceGDPR and CCPA
RiskTCPA, outbound calling
Outbound calls go only to consented numbers, inside the windows your policy sets.
How it is enforced
Your policy sets the consented list and the calling window, and a call outside either is refused before it dials.
EvidenceConsent policy on request
The frameworks we hold to, and their marks.
Every framework a regulated buyer asks about, with the mark we set beside it. The report behind each one comes with the package.

SOC 2 Type 1 and Type 2SOC 2 Type 1 and 2
How controls are built and run

ISO 27001:2022
Information security

ISO 42001:2023
Management system for AI

HIPAA
Protected health information

GDPR
EU personal data

EU AI Act
AI risk and transparency

CSA STAR Level One
Cloud security self-assessment

FedRAMP
US federal cloud security

PCI DSS
Cardholder data

CCPA
California personal data

DORA
Operational resilience

ISO 17442:2020
Legal entity identifier
Who issued each certification, its reference and when it expires come with the package.
Request the security packageRead the reports before you sign.
Ask for the package and we send the evidence behind each framework, the data-processing terms and a scoped answer to your questionnaire, under NDA where a report requires it.
Retention and consent settings come as they would be set for your estate, and an architect walks your auditor through where each control runs.
How a review runs
From the first request to your auditor's sign-off.
Bring one call type. Leave with an architecture.

Built for the most regulated floor
A working session with an engineer who has deployed inside a bank’s perimeter. We map your telephony, data boundary and handoff rules, and tell you what we would not automate.