Trust center

Security and governance you can show your buyer.

An AI answering your phone touches customer PII on every call. Here is exactly how we protect it, what we're certified for, and the controls you hold.

Security baseline

Encryption in transit

TLS 1.2+ on every connection — console, API, webhooks, and telephony signaling.

Encryption at rest

Recordings, transcripts, and customer data encrypted at rest in managed infrastructure.

Role-based access control

Owner, admin, member, and QA reviewer roles with least-privilege defaults.

Audit logs

Every admin action — config changes, approvals, invitations, key usage — recorded with actor, target, and IP.

Secret handling

Integration credentials stored encrypted and never exposed in configs, logs, or API responses.

Backups & recovery

Automated backups with tested restore procedures.

Infrastructure monitoring

Uptime and health monitoring with alerting on anomalies and sync failures.

Environment separation

Production isolated from staging and development, with separate credentials.

Compliance posture

We say "in progress" when it's in progress. No badge inflation.

SOC 2 Type II

In progress

Controls implemented and audit underway. Report available under NDA when issued.

HIPAA-ready architecture

Available

PHI-aware data handling, redaction, and retention controls. BAA offered on enterprise plans targeting healthcare.

GDPR-aligned controls

Available

Data subject export and deletion workflows, retention limits, and regional data controls.

PCI-aware design

By design

Payments run through certified processors (Stripe, LawPay). Card data never touches RingNest systems.

Privacy controls in your hands

Configurable retention

Set how long transcripts and recordings live — 30 days to multi-year — per workspace.

PII redaction

Automatic redaction of card numbers, SSNs, and other sensitive strings in transcripts and analytics.

Recording consent modes

One-party (record silently where legal), two-party (require caller consent), or announce (state recording up front). Match your state's rules per location.

Delete & export workflows

Delete a caller's data or export everything you own — via console or API.

Customer-owned boundaries

Your data trains nothing shared. Knowledge, transcripts, and leads stay inside your tenant.

Regional data controls

Choose where your data lives — US today, EU on the enterprise roadmap.

AI safety & governance

The part most vendors hand-wave. An AI speaking for your business needs the same controls you'd give a new hire: rules, supervision, and a review process — and yours are enforced by the platform, not a promise.

Topic guardrails

Define what the receptionist must never do — quote firm prices, give medical advice, discuss competitors — enforced per intent and topic.

Confidence-based fallback

Below a confidence threshold you set, the AI stops answering and escalates to a human. No guessing at your customers' expense.

Human escalation triggers

Emergencies, complaints, VIPs, and explicit requests for a human always route out — configurable, and logged.

Approval workflow for changes

Prompt, playbook, and policy changes create a pending version that an owner or admin must approve before it answers a single call.

Version history & change logs

Every agent version is snapshotted with who changed what, who approved it, and when it went live. Roll back in one click.

Conversation review visibility

QA reviewers score real transcripts on a rubric; flagged calls surface for coaching and knowledge fixes.

Running a security review?

We'll complete your security questionnaire, walk your team through the architecture, and provide audit evidence under NDA. Enterprise plans include a dedicated security contact.