Security practices

Plain-language description of what Octone does today. This is not a SOC 2 or HIPAA certification.

Encryption

Traffic to octone.co uses HTTPS. Call media uses the phone provider’s encrypted paths (WebRTC / SIP). Passwords are stored as hashes. SIP and plugin webhook secrets are encrypted at rest with the app secret.

Consent

When call recording is on, inbound callers can hear a consent prompt before recording starts. Tenant admins can turn that prompt off on Company setup — that choice is logged.

Access logs

Octone writes an audit row when someone views a recording, exports the call log, changes users, or toggles recording. Admins see that at Admin → Audit log.

Access control

Owner / admin / manager / agent roles limit who can buy numbers, listen in, or open billing. Feature switches hide modules per company.

What certification requires

Independent SOC 2 or HIPAA certification needs a formal program, audits, and (for HIPAA) a Business Associate Agreement. Octone does not claim to be SOC 2 or HIPAA certified. If you need a BAA, request one and the platform owner will follow up.

Help: compliance vs certification