Softtop is SOC 2 Type II certified, confirming that security controls covering availability, confidentiality, and data integrity have been independently audited and verified by a third-party assessor. The certification is renewed annually and the current report is available to enterprise customers under NDA. SOC 2 Type II certification is the standard required by enterprise IT security teams for vendor approval in regulated industries and enterprise procurement processes.
Data encryption applies at every layer of the platform. All data in transit is encrypted using TLS 1.2 or higher. All data at rest — call recordings, transcripts, customer records, message logs — is encrypted using AES-256. Encryption keys are managed using a zero-knowledge key management system so Softtop personnel cannot access customer call or message content without explicit customer authorization and a formal access request process.
Zero-trust access architecture requires authentication and authorization for every access request regardless of network location. Single sign-on via Okta, Microsoft Entra, and Google Workspace integrates with existing enterprise identity providers. Multi-factor authentication is enforced for all admin account access. Role-based access controls limit platform permissions to the minimum required for each user's specific function within the organization.
Infrastructure is hosted in geographically redundant data centers with 24/7 physical security, biometric access controls, redundant power, and automated failover. Security monitoring runs continuously with automated threat detection and defined incident response playbooks. Vulnerability disclosure and penetration testing results are available to enterprise customers on request. Privacy policy compliance covers GDPR, CCPA, and applicable telecommunications privacy regulations in every market where Softtop operates. TLS 1.3 enforced for all data in transit DDoS mitigation and WAF on all endpoints Role-based access control (RBAC) on every seat Customer notification within 72 hours of breach Full A-attestation on originating US calls. Robocall mitigation certification filed with FCC. EU data residency options, DPA templates, and automated data subject request workflows. All data encrypted at rest with AES-256. TLS 1.3 enforced for all API traffic, SIP signalling, and media. Your call recordings, transcripts, and contact data belong to you. We never sell, rent, or share it with third parties. Submit a deletion request and all your data is purged within 30 days — from live systems and all backups. Export your full dataset at any time in open formats. No lock-in, no exit fees. We publish a full list of every sub-processor who touches your data with the reason and data category. All data is stored in AWS US-East and US-West regions by default. EU data residency is available on Enterprise plans. Yes. Customers and prospects can request the full SOC 2 Type II report by contacting our security team. An NDA is required. We will notify affected customers within 72 hours of confirming a breach, consistent with GDPR and applicable US state laws. A full incident report follows within 30 days. Yes. All call recordings are encrypted at rest with AES-256 and in transit with TLS 1.3. PCI and PHI redaction is available as an add-on. Yes. We support SAML 2.0, Okta, Azure AD, and Google Workspace for SSO. MFA is enforced on all admin accounts and can be mandated org-wide. How do I report a security vulnerability? Email security@softtop.tech with a description of the issue. We commit to a 48-hour acknowledgement and responsible remediation before any public disclosure. From regulated healthcare to PCI-scoped finance — teams who chose Softtop for security. Our compliance officer signed off on Softtop in one review. SOC 2 Type II, BAA ready, end-to-end encryption. Exactly what we needed.