Security, compliance & data residency
We own every layer — carrier, SBC, PBX, messaging, and AI — and run it in your region. Here's exactly what protects your calls, messages, and data, and which standards we hold today.
Customer trust comes first
Protecting your data isn't a bolt-on — it's the foundation. Because we own every layer of the stack (carrier, SBC, PBX, messaging, and AI) and run it in your region, we can be precise about what protects you. Everything below is backed by what we actually ship — no badges we don't hold.
Compliance & standards
We build to — and, where a program is in progress or an offering rather than a held certification, we say so plainly — the following standards and frameworks:
STIR/SHAKEN
STIR/SHAKEN caller ID authentication enforced at the carrier level via our upstream provider. All outbound calls carry the appropriate attestation level.
Licensed Carrier
Operated as a licensed telecommunications carrier — CRTC-registered in Canada and FCC-compliant in the US.
HIPAA Ready
BAA-eligible infrastructure for healthcare customers handling PHI over voice and messaging.
10DLC Registered
US A2P 10DLC brand and campaign registration for compliant application-to-person business messaging, handled with our messaging carrier.
CASL Compliant
Canada's Anti-Spam Legislation honored end-to-end: express-consent gating and bilingual STOP/ARRÊT opt-out enforced on messaging campaigns.
PIPEDA Compliant
Compliant with Canada's federal privacy law (PIPEDA) — including self-serve export and deletion of personal information.
CCPA/CPRA
Consumer privacy rights honored for California residents — right to know, delete, correct, and opt out of sale.
GDPR — DPA Available
Data Processing Agreement (DPA) and data-residency options available for European customers and partners; right-to-erasure and data portability supported.
Encryption & call security
Calls, messages, and stored data are encrypted end-to-end across the platform.
TLS 1.3 in transit and AES-256 (ZFS native encryption) at rest for databases and media.
DTLS-SRTP encrypted media for WebRTC calls — handled at the media-relay layer.
STIR/SHAKEN caller-ID attestation on outbound calls, enforced at the carrier level.
E911 with §506(b) (RAY BAUM’s Act) dispatch notifications to a configured contact.
Data residency & sovereignty
Your data stays in your region. Canadian customers' media — voicemails, call recordings, and generated audio — is stored in-region in Canada, and call routing enforces regional boundaries at the infrastructure level. We honor Canada's federal privacy law (PIPEDA) and anti-spam legislation (CASL), US A2P 10DLC registration for business messaging, and offer a Data Processing Agreement for customers and partners with European data-residency needs.
Native AI
Our AI — transcription, sentiment, summaries, intent, and voice agents — is native to the platform, running on infrastructure we own and operate in your region. Your conversations are never handed off to a third-party model API, which is what makes our sovereignty and residency commitments real rather than aspirational.
Your data & privacy rights
You stay in control of personal data on the platform.
Self-serve data export and deletion of personal information (PIPEDA / GDPR Art. 17).
PII anonymized on account cancellation across voice and messaging records.
CASL express-consent gating and bilingual STOP/ARRÊT opt-out on messaging campaigns.
CCPA/CPRA consumer rights — know, delete, correct, and opt out of sale.
Reliability & status
Our infrastructure runs with built-in redundancy, encrypted backups, and continuous uptime monitoring. Our uptime commitments and service-credit terms are published, and current platform health is live and public — no sign-in required.