Security & Compliance
Enterprise-Ready Security. Compliant From Day One.
1stDay runs on a SOC 2-attested, ISO 27001-certified, HIPAA-compliant voice AI platform, backed by our own HIPAA-aligned policies and Business Associate Agreements. Your compliance team gets the controls regulated industries expect, without rip-and-replace.
Platform built for PHI, with Business Associate Agreements available
Delivered on a SOC 2-attested platform
Delivered on an ISO 27001-certified platform
Privacy and security controls aligned to GDPR requirements
Here are the compliance frameworks that our platform follows, which showcase our adherence to industry-standard security guidelines and practices.
SOC 2
✓ CompliantSOC 2 is a voluntary compliance standard for service organizations, developed by the American Institute of CPAs (AICPA), which specifies how organizations should manage customer data. The standard is based on the following Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.
ISO 27001 v2022
✓ CompliantThe updated version of the ISO 27001 standard, reflecting the latest best practices and improvements in information security management.
HIPAA
✓ CompliantThe Health Insurance Portability and Accountability Act, a U.S. law that mandates standards for protecting sensitive patient health information.
GDPR
✓ CompliantThe General Data Protection Regulation, a comprehensive data protection law in the EU, governs how organizations must protect personal data and privacy.
Security built into the platform.
Flexible deployment
Cloud, private cloud and enterprise on-premise deployment options for teams with strict infrastructure requirements.
Encryption end to end
AES-256 encryption at rest and TLS 1.3 in transit for recordings, transcripts and data.
Role-based access
Granular permissions and full audit logs so every action is attributable and reviewable.
Human-in-the-loop
Clear escalation rules put people in control of sensitive decisions and exceptions.
Controls built into every workflow.
Audit trail on every conversation
Timestamped records of identity checks, actions taken and confirmations sent.
Verification before action
Agents confirm identity against your rules before accessing or changing any record.
Least-privilege integrations
Connected systems expose only the records and actions you approve.
Consent and contact controls
Outbound workflows respect consent, timing and do-not-contact requirements.
Human escalation
Sensitive or ambiguous situations are routed to your staff with full context.
Business associate agreements
Available for healthcare customers handling protected health information.
Connects to any enterprise system, across every vertical.
CRM, ERP, ITSM, EHR, billing and payments. 1stDay agents read from and write to the systems of record you already run, so every conversation ends with the work completed where your team works.







Representative systems shown. Product names and trademarks are the property of their respective owners and do not imply endorsement.
Questions from your security team?
We'll walk through architecture, data handling and documentation with your reviewers.