Security Architecture
Six layers of protection on every account.
Data Encryption
- AES-256 encryption for all data at rest
- TLS 1.3 enforced for all data in transit
- Per-tenant encryption key management
- Automatic key rotation every 90 days
Infrastructure Security
- Tier-1 enterprise-grade data centers
- Multi-region redundancy across AWS
- DDoS mitigation and WAF on all endpoints
- Automated vulnerability patching within 24 hrs
Continuous Monitoring
- 24/7 SIEM and intrusion detection
- Real-time anomaly alerts with auto-quarantine
- Full audit log on every admin action
- Live stream to Splunk, Datadog, or your SIEM
Access Control
- Role-based access control (RBAC) on every seat
- SSO via SAML 2.0, Okta, and Azure AD
- MFA enforced for all admin accounts
- Zero-trust internal network architecture
Incident Response
- Dedicated security team on call 24/7
- < 2 hour initial response SLA
- Public incident history at status.softtop.tech
- Customer notification within 72 hours of breach
Network Security
- STIR/SHAKEN attestation on all US calls
- Carrier-grade fraud detection and blocking
- IP allow-listing and geo-restriction controls
- Private interconnects available for enterprise
Data Privacy
Privacy is a feature, not a footnote.
We designed Softtop so that customers have full control over their data from day one — who sees it, where it lives, and how long it's kept. Our practices align with GDPR data privacy principles.
You own your data
Your call recordings, transcripts, and contact data belong to you. We never sell, rent, or share it with third parties.
Right to erasure
Submit a deletion request and all your data is purged within 30 days — from live systems and all backups.
Data portability
Export your full dataset at any time in open formats. No lock-in, no exit fees.
Sub-processor transparency
We publish a full list of every sub-processor who touches your data with the reason and data category.
Penetration Testing
Annual third-party pen tests — results shared on request.
We engage an independent security firm every year to conduct full-scope penetration testing across our network, APIs, and application layer. Customers can request the executive summary under NDA.
Network & infrastructure scope
API and web application layer
Internal privilege escalation tests
Social engineering assessments
Responsible Disclosure
Found a vulnerability? We want to know.
Softtop operates a responsible disclosure programme. If you discover a security vulnerability in our systems, please report it to our enterprise security team. We commit to a 48-hour acknowledgement and a 90-day remediation window before public disclosure.
FAQ