Skip to main content

Security, compliance & data residency

We own every layer — carrier, SBC, PBX, messaging, and AI — and run it in your region. Here's exactly what protects your calls, messages, and data, and which standards we hold today.

Customer trust comes first

Protecting your data isn't a bolt-on — it's the foundation. Because we own every layer of the stack (carrier, SBC, PBX, messaging, and AI) and run it in your region, we can be precise about what protects you. Everything below is backed by what we actually ship — no badges we don't hold.

Compliance & standards

We build to — and, where a program is in progress or an offering rather than a held certification, we say so plainly — the following standards and frameworks:

STIR/SHAKEN

STIR/SHAKEN caller ID authentication enforced at the carrier level via our upstream provider. All outbound calls carry the appropriate attestation level.

Licensed Carrier

Operated as a licensed telecommunications carrier — CRTC-registered in Canada and FCC-compliant in the US.

HIPAA Ready

BAA-eligible infrastructure for healthcare customers handling PHI over voice and messaging.

10DLC Registered

US A2P 10DLC brand and campaign registration for compliant application-to-person business messaging, handled with our messaging carrier.

CASL Compliant

Canada's Anti-Spam Legislation honored end-to-end: express-consent gating and bilingual STOP/ARRÊT opt-out enforced on messaging campaigns.

PIPEDA Compliant

Compliant with Canada's federal privacy law (PIPEDA) — including self-serve export and deletion of personal information.

CCPA/CPRA

Consumer privacy rights honored for California residents — right to know, delete, correct, and opt out of sale.

GDPR — DPA Available

Data Processing Agreement (DPA) and data-residency options available for European customers and partners; right-to-erasure and data portability supported.

Encryption & call security

Calls, messages, and stored data are encrypted end-to-end across the platform.

  • TLS 1.3 in transit and AES-256 (ZFS native encryption) at rest for databases and media.

  • DTLS-SRTP encrypted media for WebRTC calls — handled at the media-relay layer.

  • STIR/SHAKEN caller-ID attestation on outbound calls, enforced at the carrier level.

  • E911 with §506(b) (RAY BAUM’s Act) dispatch notifications to a configured contact.

Data residency & sovereignty

Your data stays in your region. Canadian customers' media — voicemails, call recordings, and generated audio — is stored in-region in Canada, and call routing enforces regional boundaries at the infrastructure level. We honor Canada's federal privacy law (PIPEDA) and anti-spam legislation (CASL), US A2P 10DLC registration for business messaging, and offer a Data Processing Agreement for customers and partners with European data-residency needs.

Native AI

Our AI — transcription, sentiment, summaries, intent, and voice agents — is native to the platform, running on infrastructure we own and operate in your region. Your conversations are never handed off to a third-party model API, which is what makes our sovereignty and residency commitments real rather than aspirational.

Your data & privacy rights

You stay in control of personal data on the platform.

  • Self-serve data export and deletion of personal information (PIPEDA / GDPR Art. 17).

  • PII anonymized on account cancellation across voice and messaging records.

  • CASL express-consent gating and bilingual STOP/ARRÊT opt-out on messaging campaigns.

  • CCPA/CPRA consumer rights — know, delete, correct, and opt out of sale.

Reliability & status

Our infrastructure runs with built-in redundancy, encrypted backups, and continuous uptime monitoring. Our uptime commitments and service-credit terms are published, and current platform health is live and public — no sign-in required.