Security & Trust

Your data is safe.
We make sure of it.

Softtop is built on a security-first foundation — SOC 2 Type II certified, end-to-end encryption, zero-trust architecture, STIR/SHAKEN attestation, and 24/7 threat monitoring backed by a dedicated security engineering team.

SOC 2 Type IIEnd-to-End EncryptedSTIR/SHAKEN AttestedGDPR ReadyZero-Trust Architecture24/7 MonitoringAES-256 at Rest
Security Architecture

Six layers of protection on every account.

Data Encryption
  • AES-256 encryption for all data at rest
  • TLS 1.3 enforced for all data in transit
  • Per-tenant encryption key management
  • Automatic key rotation every 90 days
Infrastructure Security
  • Tier-1 enterprise-grade data centers
  • Multi-region redundancy across AWS
  • DDoS mitigation and WAF on all endpoints
  • Automated vulnerability patching within 24 hrs
Continuous Monitoring
Access Control
  • Role-based access control (RBAC) on every seat
  • SSO via SAML 2.0, Okta, and Azure AD
  • MFA enforced for all admin accounts
  • Zero-trust internal network architecture
Incident Response
  • Dedicated security team on call 24/7
  • < 2 hour initial response SLA
  • Public incident history at status.softtop.tech
  • Customer notification within 72 hours of breach
Network Security
  • STIR/SHAKEN attestation on all US calls
  • Carrier-grade fraud detection and blocking
  • IP allow-listing and geo-restriction controls
  • Private interconnects available for enterprise
Compliance

Built for the standards that matter to your industry.

STIR/SHAKEN

Full A-attestation on originating US calls. Robocall mitigation certification filed with FCC.

GDPR Ready

EU data residency options, DPA templates, and automated data subject request workflows.

Compliance-Ready Arch

Business Associate Agreements available on qualifying plans. PHI handling controls and call recording redaction built in.

PCI Scope Reduced

Cardholder data never touches Softtop systems. PCI-compliant call recording redaction for finance and contact centers.

Zero-Trust Network

All internal traffic is authenticated and encrypted. No implicit trust — every request is verified, following CISA cybersecurity best practices.

AES-256 + TLS 1.3

All data encrypted at rest with AES-256. TLS 1.3 enforced for all API traffic, SIP signalling, and media.

Data Privacy

Privacy is a feature, not a footnote.

We designed Softtop so that customers have full control over their data from day one — who sees it, where it lives, and how long it's kept. Our practices align with GDPR data privacy principles.

You own your data
Your call recordings, transcripts, and contact data belong to you. We never sell, rent, or share it with third parties.
Right to erasure
Submit a deletion request and all your data is purged within 30 days — from live systems and all backups.
Data portability
Export your full dataset at any time in open formats. No lock-in, no exit fees.
Sub-processor transparency
We publish a full list of every sub-processor who touches your data with the reason and data category.
Penetration Testing

Annual third-party pen tests — results shared on request.

We engage an independent security firm every year to conduct full-scope penetration testing across our network, APIs, and application layer. Customers can request the executive summary under NDA.

Network & infrastructure scope
API and web application layer
Internal privilege escalation tests
Social engineering assessments
Responsible Disclosure

Found a vulnerability? We want to know.

Softtop operates a responsible disclosure programme. If you discover a security vulnerability in our systems, please report it to our enterprise security team. We commit to a 48-hour acknowledgement and a 90-day remediation window before public disclosure.

Trusted by Security-Conscious Teams

What Compliance Teams Say

From regulated healthcare to PCI-scoped finance — teams who chose Softtop for security.

1 audit
Sign-off

"Our compliance officer signed off on Softtop in one review. SOC 2 Type II, BAA ready, end-to-end encryption. Exactly what we needed."

S
Dr. Susan L.
CISO, CareFirst Clinics
FAQ

Security questions, answered.

All data is stored in AWS US-East and US-West regions by default. EU data residency is available on Enterprise plans.
Yes. Customers and prospects can request the full SOC 2 Type II report by contacting our security team. An NDA is required.
We will notify affected customers within 72 hours of confirming a breach, consistent with GDPR and applicable US state laws. A full incident report follows within 30 days.
Yes. All call recordings are encrypted at rest with AES-256 and in transit with TLS 1.3. PCI and PHI redaction is available as an add-on.
Yes. We support SAML 2.0, Okta, Azure AD, and Google Workspace for SSO. MFA is enforced on all admin accounts and can be mandated org-wide.
Email security@softtop.tech with a description of the issue. We commit to a 48-hour acknowledgement and responsible remediation before any public disclosure.

Security questions before you sign up?

Our security team is happy to walk you through our controls, share the SOC 2 report, or set up a technical review.