Certifications and audit scope
CallPorch is SOC 2 Type II compliant for Security, Availability, and Confidentiality for the October 2024–October 2025 audit period. Healthcare customers can request a BAA, and HIPAA-compliant tenants use database-level segregation. CallPorch encrypts data at rest with AES-256 and in transit with TLS 1.3.
- PCI-DSS Level 1 compliant payment posture; full card numbers are not stored and Stripe tokenization is used.
- Call recordings retained for 90 days.
- Transcripts and CallTrail Receipts retained for 7 years when requested for medical-record standards.
- Immutable staff-interaction audit logs retained for 24 months.
- RBAC roles: Super Admin, Location Manager, Front Desk Staff.
- SAML 2.0 supported; MFA mandatory for Admin roles.
- Subprocessors: AWS, OpenAI API under enterprise agreement, Twilio.
Audit scope: SOC 2 Type II covering Security, Availability, and Confidentiality for the October 2024 – October 2025 audit period. We describe HIPAA posture as BAA available for HIPAA-compliant tenants — CallPorch is not "HIPAA certified," because no such certification exists.
Encryption
Traffic between callers, the assistant, your team, and CallPorch is encrypted in transit with TLS 1.3. Call audio, transcripts, intake records, and SMS logs are encrypted at rest with AES-256 in our managed databases and object storage. Backups are encrypted with separately managed keys.
Access control
Inside a workspace, access is scoped by RBAC role: Super Admin, Location Manager, and Front Desk Staff. SAML 2.0 single sign-on is supported, and MFA is mandatory for Admin roles. Inside CallPorch, only a small number of operations engineers can reach production systems, and only through audited, MFA-protected paths. Production access is reviewed quarterly and revoked promptly on role change or departure.
HIPAA-compliant tenants run with database-level segregation. A BAA is available on request for healthcare customers.
Audit trail
Every view, export, change, and deletion inside a workspace is written to the audit history with a timestamp and an actor. Owners can export the audit log. Internal production access is logged in a separate system that workspace staff cannot modify.
Secure development
- Code review on every change before it ships.
- Automated dependency scanning and patching.
- Static analysis on every pull request.
- Production secrets stored in a managed secrets vault, not in code.
- Separate environments for development, staging, and production.
Monitoring and incident response
We monitor for unusual access patterns, failed-login spikes, and spikes in outbound SMS. If we detect or are notified of a security incident, our team investigates, contains, and writes a postmortem. Where an incident materially affects a customer's data, we notify the workspace owner without undue delay and within the timeframes applicable law requires.
Retention
- Call recordings retained for 90 days.
- Transcripts and CallTrail Receipts retained for 7 years when requested for medical-record standards.
- Immutable staff-interaction audit logs retained for 24 months.
Payments
CallPorch maintains a PCI-DSS Level 1 compliant payment posture. Full card numbers are not stored; Stripe tokenization is used for any card-not-present workflow.
Subprocessors
Current subprocessors: AWS (hosting and databases), the OpenAI API under an enterprise agreement (speech and language models), and Twilio (voice and SMS). Each is reviewed before adoption and re-reviewed annually. Changes are communicated to workspace owners, and the current list is confirmable at security@callporch.co.
Responsible disclosure
If you believe you've found a security issue in CallPorch, write to security@callporch.co. Include enough detail to reproduce the issue and the contact you'd like us to credit. We acknowledge within two business days and aim to remediate critical issues within seven.
Please do not test on real customer workspaces, do not exfiltrate data beyond what's needed to demonstrate the issue, and do not publicly disclose before we've had a chance to fix.
Security questionnaires
Procurement or compliance teams can request our SOC 2 Type II report, a BAA, or our standard security overview at security@callporch.co. We describe scope precisely rather than displaying badges: HIPAA is handled as BAA available for HIPAA-compliant tenants, not as a certification claim.
CallPorch, LLC — 1210 Hamblen Rd Ste 875, Kingwood, TX 77339. Reviewed each quarter.
CallPorch may route calls, draft SMS, and hold slots in Pending status. Final appointment confirmation, medical triage overrides, and pricing quotes require a human.
Questions about this page? Email support@callporch.co.
Plain-language summaries. Operative terms live in your signed agreement with CallPorch.