Security & Compliance

Enterprise-Ready Security. Compliant From Day One.

1stDay runs on a SOC 2-attested, ISO 27001-certified, HIPAA-compliant voice AI platform, backed by our own HIPAA-aligned policies and Business Associate Agreements. Your compliance team gets the controls regulated industries expect, without rip-and-replace.

HIPAA

Platform built for PHI, with Business Associate Agreements available

SOC 2

Delivered on a SOC 2-attested platform

ISO 27001

Delivered on an ISO 27001-certified platform

Data protection

Privacy and security controls aligned to GDPR requirements

Certifications

Here are the compliance frameworks that our platform follows, which showcase our adherence to industry-standard security guidelines and practices.

SOC 2

✓ Compliant

SOC 2 is a voluntary compliance standard for service organizations, developed by the American Institute of CPAs (AICPA), which specifies how organizations should manage customer data. The standard is based on the following Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.

ISO 27001 v2022

✓ Compliant

The updated version of the ISO 27001 standard, reflecting the latest best practices and improvements in information security management.

HIPAA

✓ Compliant

The Health Insurance Portability and Accountability Act, a U.S. law that mandates standards for protecting sensitive patient health information.

GDPR

✓ Compliant

The General Data Protection Regulation, a comprehensive data protection law in the EU, governs how organizations must protect personal data and privacy.

Platform Controls

Security built into the platform.

Flexible deployment

Cloud, private cloud and enterprise on-premise deployment options for teams with strict infrastructure requirements.

Encryption end to end

AES-256 encryption at rest and TLS 1.3 in transit for recordings, transcripts and data.

Role-based access

Granular permissions and full audit logs so every action is attributable and reviewable.

Human-in-the-loop

Clear escalation rules put people in control of sensitive decisions and exceptions.

Practices

Controls built into every workflow.

Audit trail on every conversation

Timestamped records of identity checks, actions taken and confirmations sent.

Verification before action

Agents confirm identity against your rules before accessing or changing any record.

Least-privilege integrations

Connected systems expose only the records and actions you approve.

Consent and contact controls

Outbound workflows respect consent, timing and do-not-contact requirements.

Human escalation

Sensitive or ambiguous situations are routed to your staff with full context.

Business associate agreements

Available for healthcare customers handling protected health information.

Enterprise Integrations

Connects to any enterprise system, across every vertical.

CRM, ERP, ITSM, EHR, billing and payments. 1stDay agents read from and write to the systems of record you already run, so every conversation ends with the work completed where your team works.

Oracle
SAP
Salesforce
ServiceNow
Epic
Cerner
eClinicalWorks
athenahealth

Representative systems shown. Product names and trademarks are the property of their respective owners and do not imply endorsement.

Questions from your security team?

We'll walk through architecture, data handling and documentation with your reviewers.

Speak to sales