Trust & security

A plain statement of how we handle your data.

This is what we hand your compliance or IT team. Our controls are aligned to SOC 2, and we are not a licensed insurance producer: we do not quote, bind, or advise on coverage. We answer, route, document, and escalate calls under the rules you give us.

TCPA-aligned outbound SOC 2-aligned handling Every call recorded & logged NDA / DPA available
The posture

What's true about how we handle your data

Plain statements, so your team can check them off rather than interpret marketing language.

Agreement before access

We sign the service and data agreement during discovery, before any access is granted or data moves.

Encrypted in transit and at rest

Modern transport encryption on every integration, and encrypted storage for everything retained.

Least-privilege access

Role-based access, individually attributed. No shared accounts, no standing production access.

Audited data flows

Every integration is documented: what field moves, where it goes, and why it's needed.

Defined retention

Recording and transcript retention set with you, with deletion on the schedule you specify.

Minimum necessary

We request the narrowest data set that answers the call, and nothing beyond it.

Incident response

A documented plan with notification timelines that meet or beat your agreement terms.

Subcontractor control

Any downstream processor is disclosed to you. No surprise fourth parties.

Monitoring and logging

Access and administrative actions logged and reviewable, with alerting on anomalies.

Outbound specifics

Telephony compliance, on its own

Outbound to policyholders and leads raises obligations that have nothing to do with data security. We treat them as their own discipline.

Consent basis per attempt

Every outbound attempt is logged with the consent it relied on and where that consent came from.

Calling windows enforced

Federal and state time-of-day restrictions enforced by the dialer, not by policy alone.

Suppression honored

Do-not-call and your own suppression lists loaded before a campaign runs, with opt-outs applied immediately.

Identity verified

Numbers registered to you and signed at full attestation, so the call is provably from your organization.

More detail on branding and STIR/SHAKEN. See outbound calling
Common questions

What your compliance team will ask

Are you a licensed insurance producer?

No. We handle calls, we don't quote, bind, advise on, or sell coverage. Anything requiring a licensed producer routes to your team under the escalation rules we set together.

Will you sign our data processing agreement?

Yes, in most cases. We'll redline where a term is operationally impossible, and we do that during discovery rather than at signature.

Are calls recorded, and for how long?

Recording and transcript retention are configured with you, including the option not to retain audio at all. Deletion runs on the schedule you set.

Where is data processed and stored?

Stated explicitly in our security documentation, including region and any subprocessor. If you have a data residency requirement, raise it in discovery.

Can our auditors review your controls?

Yes. We support security reviews, questionnaires, and reasonable audit rights as part of the agreement.

Request our security documentation

We'll send the full package under NDA before the first call is answered.

Or talk to our team at (888) 775-8857