What happens to your customers’ data on our floor
Four standards apply to the work we do. Here is what each one obliges us to do, and where we stand on it today.
HIPAA
- What the standard requires
- Health data may only be handled by trained staff under a business associate agreement.
- Where we stand
- Agents on healthcare accounts train annually, under a signed BAA.
Applies to healthcare.
PCI-DSS
- What the standard requires
- Card data must be captured and stored inside a controlled environment.
- Where we stand
- Payments route to a PCI-compliant IVR. Agents never see a card number.
Applies to insurance, financial services.
SOC 2 Type II
- What the standard requires
- An independent auditor tests your controls over months, not on one day.
- Where we stand
- Audit in progress, Q2 2027. Control evidence available on request.
Applies to insurance, healthcare, financial services, information technology.
GDPR
- What the standard requires
- EU and UK personal data carries transfer and subject-access obligations.
- Where we stand
- EU and UK data stays in region. DPA and SCCs on request.
Applies to real estate, information technology.
Data handling, specifically
The answers a security reviewer asks for once the standards are out of the way.
- Encryption at rest
- AES-256 on every customer data store
- Encryption in transit
- TLS 1.2 or higher, no plaintext fallback
- Agent screening
- Background and reference checks before floor access
- Floor policy
- Clean desk: no phones, no paper, no removable media
- Call recording retention
- 90 days by default, configurable per contract
- Access model
- Minimum necessary — only the fields the task needs
Contract documents — the business associate agreement, the data processing agreement and the standard contractual clauses — are available on request before any data is exchanged.
Twenty minutes, and you will know how this would run.
Tell us your volume and your hours. You get a staffing plan and the security brief — before anyone asks you for a contract.
