Security practices
Plain-language description of what Octone does today. This is not a SOC 2 or HIPAA certification.
Encryption
Traffic to octone.co uses HTTPS. Call media uses the phone provider’s encrypted paths (WebRTC / SIP). Passwords are stored as hashes. SIP and plugin webhook secrets are encrypted at rest with the app secret.
Consent
When the package includes call recording, tenant admins can turn Record calls on or off at Company setup. When recording is on, inbound callers can hear a consent prompt before recording starts. Admins can turn that prompt off. Both choices are logged. If recording is off for the package or the tenant, Octone never starts a recording.
Access logs
Octone writes an audit row when someone views a recording, exports the call log, changes users, or toggles recording. Admins see that at Admin → Audit log.
Access control
Owner / admin / manager / agent roles limit who can buy numbers, listen in, or open billing. Feature switches hide modules per company.
What certification requires
Independent SOC 2 or HIPAA certification needs a formal program, audits, and (for HIPAA) a Business Associate Agreement. Octone does not claim to be SOC 2 or HIPAA certified. If you need a BAA, request one and the platform owner will follow up.
