Home / Security
Security & trust
SimpleCX shows you exactly what it will build before anything goes live, answers only from your own account, and keeps your data where you choose. Simple on the surface. Careful underneath.
ISO 27001 certified, encrypted in transit and at rest, and independently penetration-tested — on the CallCorp platform.
Trust by design
The way SimpleCX behaves is the first layer of security. Nothing changes without your say-so, and answers come from your data — not guesses.
SimpleCX shows you the full design before anything goes live. Nothing is created until you approve it — and every configuration is fully reversible.
When you ask about your operation, answers are grounded and cited from your own account. The run assistant is strictly read-only — it reports, it never reconfigures.
Keep recordings and data in your own AWS S3, Azure, Google Cloud, or SFTP. Bring-your-own storage means data residency is on your terms, not ours.
Certifications & compliance
We're careful to say exactly what's true. One certification we hold outright — the rest are frameworks we support you in meeting.
ISO 27001 — certified. Our information-security management is independently certified to the ISO 27001 standard. This is a certification we hold.
SimpleCX supports HIPAA workflows and works with you to help you meet your HIPAA obligations, including business-associate arrangements.
Our controls are designed to support SOC 2 objectives and help you satisfy the requirements your auditors and customers expect.
SimpleCX supports PCI DSS by helping you handle cardholder data in line with the standard's requirements.
Features like bring-your-own storage and data residency help you meet GDPR obligations for the data you process.
Certification scope and details are provided on request. ISO 27001 is the only certification we hold; HIPAA, SOC 2, PCI DSS and GDPR are frameworks we help you meet.
Access & encryption
The controls behind the product — who gets in, and how your data is protected while it moves and while it rests.
MFA protects every account, so a password alone is never enough to get in.
Connect your identity provider over SAML and manage access from the tools you already run.
All traffic is protected with TLS, so data is encrypted as it moves between you and SimpleCX.
Stored data is encrypted at rest — including in the storage you bring, kept where you choose.
Independent third parties test our defenses, so weaknesses are found and fixed before they matter.
SimpleCX runs on the CallCorp platform — the same infrastructure trusted to carry real contact-center traffic every day.
Questions
Where you choose. With bring-your-own storage, recordings and data can stay in your own AWS S3, Azure, Google Cloud, or SFTP — so data residency is on your terms. Your data, your storage.
We don't sell your data. The answers you get about your operation are grounded in your own account, and the run assistant is read-only — it reports, it never reconfigures. Full data-handling details are available on request.
We hold ISO 27001 certification for our information-security management. We also support HIPAA, SOC 2, PCI DSS and GDPR — meaning we help you meet those frameworks — but those are not certifications we hold. Certification scope and details are provided on request.
Yes. SimpleCX previews the full design before anything goes live, nothing is built without your approval, and configuration is fully reversible. You're always in control of what changes.
Describe your business, preview the whole design, and decide what to build. Free, and no account required to start.
Try it free →