Trust & Compliance

Built for the teams your security review answers to.

BeyondCalls runs regulated, high-volume outbound for enterprise revenue teams. Every dial is consent-aware, every record is encrypted, and every control your legal, security and compliance reviewers ask about is documented and available on request.

SOC 2 Type II
Audit in progress
GDPR & UK GDPR
DPA on request
CCPA / CPRA
No data sale
TCPA & TSR
DNC enforced
STIR/SHAKEN
A-attestation
AES-256 · TLS 1.3
At rest & in transit

TCPA

DNC list enforcement, consent tracking and call-time restrictions applied before every dial.

GDPR

Data minimization, right to erasure, consent management and a signed DPA for enterprise customers.

CCPA / CPRA

Right to know, delete and opt-out. We never sell personal information.

STIR/SHAKEN

Caller-ID authentication with full A-level attestation on outbound calls.

CAN-SPAM

Unsubscribe links, sender identification and honest headers on every message.

TSR

Calling-hour restrictions, DNC compliance and mandatory disclosures built in.

Telephony Compliance

  • DNC Enforcement: Global and per-organization Do-Not-Call lists. Automatic blocking before every dial; DND dispositions auto-add to the blocklist.
  • Calling Hours: Configurable per-timezone calling windows. Default 8am–9pm prospect-local time.
  • Caller ID: STIR/SHAKEN attestation. No spoofing. Dedicated DIDs per rep for full traceability.
  • Recording Consent: Configurable per campaign; customers control state-level consent settings.
  • AMD Transparency: Answering-machine detection is labeled in call metadata and never used to circumvent consent.
  • Smart DID Rotation: Region-matched caller ID with per-DID volume caps to prevent spam flagging.

Data Protection

  • Encryption: TLS 1.3 in transit, AES-256 at rest; SIP credentials sealed with AES-256-GCM.
  • Access Control: Role-based (Owner / Manager / SDR), enforced server-side with full audit logging.
  • Data Residency: US-based hosting (GCP us-central1). EU data processing available on request.
  • DPA: Data Processing Agreement covering GDPR Article 28 available for enterprise customers.
  • Sub-Processors: Telephony, auth, AI, real-time and database providers. Full list on request.
  • Retention: Configurable per organization. Default 90 days for recordings, 2 years for metadata.

GDPR Specifics

  • Lawful Basis: Contract performance, legitimate interest (B2B outreach) and consent (recordings, cookies).
  • Data-Subject Rights: Access, rectification, erasure, portability, restriction and objection.
  • International Transfers: Standard Contractual Clauses (SCCs) for EU–US data transfers.
  • DPIA: Impact assessments conducted for high-risk processing activities.
  • DPO: Reach our Data Protection Officer at dpo@datafrontier.co.
Submit a data-subject request

Regional Compliance

RegionRegulationStatus
United StatesTCPA, TSR, CAN-SPAM, CCPA/CPRA, State DNC lawsCompliant
European UnionGDPR, ePrivacy Directive, EU AI ActCompliant
United KingdomUK GDPR, PECR, ICO guidelinesCompliant
CanadaPIPEDA, CASL, CRTC DNCCompliant
AustraliaPrivacy Act, Do Not Call Register, Spam ActSupported
IndiaDPDP Act 2023, TRAI DNCSupported

Resilient infrastructure

Dual-carrier voice fabric with automatic failover and connection-pool hardening.

Secrets management

Credentials held in a managed vault, never in source. Least-privilege service accounts.

Least-privilege access

Org-scoped RBAC enforced on every API surface, with cross-org isolation.

Full audit trail

Every dial, bridge and disposition is event-logged and queryable for review.

Security review?

We'll walk your team through every control.

Request our SOC 2 report progress, subprocessor list, DPA and pen-test summary — or send your security questionnaire and we'll turn it around fast.

Compliance compliance@datafrontier.co · DPO dpo@datafrontier.co · Legal legal@datafrontier.co