Encryption in transit
TLS 1.2+ on every connection — console, API, webhooks, and telephony signaling.
Trust center
An AI answering your phone touches customer PII on every call. Here is exactly how we protect it, what we're certified for, and the controls you hold.
Encryption in transit
TLS 1.2+ on every connection — console, API, webhooks, and telephony signaling.
Encryption at rest
Recordings, transcripts, and customer data encrypted at rest in managed infrastructure.
Role-based access control
Owner, admin, member, and QA reviewer roles with least-privilege defaults.
Audit logs
Every admin action — config changes, approvals, invitations, key usage — recorded with actor, target, and IP.
Secret handling
Integration credentials stored encrypted and never exposed in configs, logs, or API responses.
Backups & recovery
Automated backups with tested restore procedures.
Infrastructure monitoring
Uptime and health monitoring with alerting on anomalies and sync failures.
Environment separation
Production isolated from staging and development, with separate credentials.
We say "in progress" when it's in progress. No badge inflation.
SOC 2 Type II
In progressControls implemented and audit underway. Report available under NDA when issued.
HIPAA-ready architecture
AvailablePHI-aware data handling, redaction, and retention controls. BAA offered on enterprise plans targeting healthcare.
GDPR-aligned controls
AvailableData subject export and deletion workflows, retention limits, and regional data controls.
PCI-aware design
By designPayments run through certified processors (Stripe, LawPay). Card data never touches RingNest systems.
Configurable retention
Set how long transcripts and recordings live — 30 days to multi-year — per workspace.
PII redaction
Automatic redaction of card numbers, SSNs, and other sensitive strings in transcripts and analytics.
Recording consent modes
One-party (record silently where legal), two-party (require caller consent), or announce (state recording up front). Match your state's rules per location.
Delete & export workflows
Delete a caller's data or export everything you own — via console or API.
Customer-owned boundaries
Your data trains nothing shared. Knowledge, transcripts, and leads stay inside your tenant.
Regional data controls
Choose where your data lives — US today, EU on the enterprise roadmap.
The part most vendors hand-wave. An AI speaking for your business needs the same controls you'd give a new hire: rules, supervision, and a review process — and yours are enforced by the platform, not a promise.
Topic guardrails
Define what the receptionist must never do — quote firm prices, give medical advice, discuss competitors — enforced per intent and topic.
Confidence-based fallback
Below a confidence threshold you set, the AI stops answering and escalates to a human. No guessing at your customers' expense.
Human escalation triggers
Emergencies, complaints, VIPs, and explicit requests for a human always route out — configurable, and logged.
Approval workflow for changes
Prompt, playbook, and policy changes create a pending version that an owner or admin must approve before it answers a single call.
Version history & change logs
Every agent version is snapshotted with who changed what, who approved it, and when it went live. Roll back in one click.
Conversation review visibility
QA reviewers score real transcripts on a rubric; flagged calls surface for coaching and knowledge fixes.
We'll complete your security questionnaire, walk your team through the architecture, and provide audit evidence under NDA. Enterprise plans include a dedicated security contact.