Compliance
Platform, Security & Integrations
Compliance
Certifications and regulations like GDPR, PCI DSS, and ISO 27001 aren’t just checkboxes. They’re independent proof that you handle your data and your customers’ data properly.

GDPR Compliance →
How we handle call data, recordings, and customer information in line with the EU’s data privacy law.
PCI DSS Requirements →
Call recording and handling practices that support PCI DSS requirements for any call that might include payment card details.
ISO 27001 Certification →
The information security standard behind how we manage and audit the underlying infrastructure for your phone system.
Curious what this would look like for your team?
These three certifications cover the areas where a phone system most often touches regulated data. GDPR covers European customer records. PCI DSS covers payment card details that pass through a call. ISO 27001 covers the underlying infrastructure security practices.
None of this lives in a policy document nobody reads. GDPR principles shape how long we retain call recordings and how you can request deletion. PCI DSS requirements shape how payment-related calls get recorded and stored, or deliberately not recorded at all. ISO 27001 shapes the access controls and audit trails behind the infrastructure itself. See our PCI DSS Compliance page for more detail.
Does your business operate under a regulation not listed here, such as HIPAA or SOC 2? Tell us during a meeting. We’ll walk through what our existing controls already cover, and what would need a custom arrangement instead. Most requests turn out closer to the first category than the second, since these three frameworks overlap with a lot of other standards already. GDPR, PCI DSS, and ISO 27001 between them touch data privacy, payment handling, and infrastructure security. Most other named frameworks end up mapping closely to one of those three areas.