Security practices

Plain-language description of what Octone does today. This is not a SOC 2 or HIPAA certification.

Encryption

Traffic to octone.co uses HTTPS. Call media uses the phone provider’s encrypted paths (WebRTC / SIP). Passwords are stored as hashes. SIP and plugin webhook secrets are encrypted at rest with the app secret.

Consent

When the package includes call recording, tenant admins can turn Record calls on or off at Company setup. When recording is on, inbound callers can hear a consent prompt before recording starts. Admins can turn that prompt off. Both choices are logged. If recording is off for the package or the tenant, Octone never starts a recording.

Access logs

Octone writes an audit row when someone views a recording, exports the call log, changes users, or toggles recording. Admins see that at Admin → Audit log.

Access control

Owner / admin / manager / agent roles limit who can buy numbers, listen in, or open billing. Feature switches hide modules per company.

What certification requires

Independent SOC 2 or HIPAA certification needs a formal program, audits, and (for HIPAA) a Business Associate Agreement. Octone does not claim to be SOC 2 or HIPAA certified. If you need a BAA, request one and the platform owner will follow up.

Help: compliance vs certification