A plain statement of how we handle your data.
This is what we hand your compliance or IT team. Our controls are aligned to SOC 2, and we are not a licensed insurance producer: we do not quote, bind, or advise on coverage. We answer, route, document, and escalate calls under the rules you give us.
What's true about how we handle your data
Plain statements, so your team can check them off rather than interpret marketing language.
Agreement before access
We sign the service and data agreement during discovery, before any access is granted or data moves.
Encrypted in transit and at rest
Modern transport encryption on every integration, and encrypted storage for everything retained.
Least-privilege access
Role-based access, individually attributed. No shared accounts, no standing production access.
Audited data flows
Every integration is documented: what field moves, where it goes, and why it's needed.
Defined retention
Recording and transcript retention set with you, with deletion on the schedule you specify.
Minimum necessary
We request the narrowest data set that answers the call, and nothing beyond it.
Incident response
A documented plan with notification timelines that meet or beat your agreement terms.
Subcontractor control
Any downstream processor is disclosed to you. No surprise fourth parties.
Monitoring and logging
Access and administrative actions logged and reviewable, with alerting on anomalies.
Telephony compliance, on its own
Outbound to policyholders and leads raises obligations that have nothing to do with data security. We treat them as their own discipline.
Consent basis per attempt
Every outbound attempt is logged with the consent it relied on and where that consent came from.
Calling windows enforced
Federal and state time-of-day restrictions enforced by the dialer, not by policy alone.
Suppression honored
Do-not-call and your own suppression lists loaded before a campaign runs, with opt-outs applied immediately.
Identity verified
Numbers registered to you and signed at full attestation, so the call is provably from your organization.
What your compliance team will ask
Are you a licensed insurance producer?
No. We handle calls, we don't quote, bind, advise on, or sell coverage. Anything requiring a licensed producer routes to your team under the escalation rules we set together.
Will you sign our data processing agreement?
Yes, in most cases. We'll redline where a term is operationally impossible, and we do that during discovery rather than at signature.
Are calls recorded, and for how long?
Recording and transcript retention are configured with you, including the option not to retain audio at all. Deletion runs on the schedule you set.
Where is data processed and stored?
Stated explicitly in our security documentation, including region and any subprocessor. If you have a data residency requirement, raise it in discovery.
Can our auditors review your controls?
Yes. We support security reviews, questionnaires, and reasonable audit rights as part of the agreement.
Request our security documentation
We'll send the full package under NDA before the first call is answered.