Security practices
Plain-language description of what Octone does today. This is not a SOC 2 or HIPAA certification.
Encryption
Traffic to octone.co uses HTTPS. Call media uses the phone provider’s encrypted paths (WebRTC / SIP). Passwords are stored as hashes. SIP and plugin webhook secrets are encrypted at rest with the app secret.
Consent
When call recording is on, inbound callers can hear a consent prompt before recording starts. Tenant admins can turn that prompt off on Company setup — that choice is logged.
Access logs
Octone writes an audit row when someone views a recording, exports the call log, changes users, or toggles recording. Admins see that at Admin → Audit log.
Access control
Owner / admin / manager / agent roles limit who can buy numbers, listen in, or open billing. Feature switches hide modules per company.
What certification requires
Independent SOC 2 or HIPAA certification needs a formal program, audits, and (for HIPAA) a Business Associate Agreement. Octone does not claim to be SOC 2 or HIPAA certified. If you need a BAA, request one and the platform owner will follow up.
