Security & compliance

Call recordings are the most sensitive data you hold

They contain identity documents, payment details and medical context, spoken out loud. This page is the detail your security review will ask for, written before you have to ask for it.

Encrypted in transit and at rest · Stored in region

Agent configuration: recording, live transcript, manager approval, escalation to a person and language, each behind its own switch

The controls, in short

The detail

What a security review usually asks next.

Where your data lives

Data residency is set when the account is created and does not move afterwards. Indian customers are provisioned in the Mumbai region, and call audio, transcripts, derived scores and CRM mirrors all stay within it. Backups stay in the same region as the primary.

Sub-processors are listed in the data processing agreement, along with what each one receives. We notify customers before a sub-processor is added.

Regulatory posture

The platform is built against the following frameworks. Where a certification is in progress rather than complete, it is described that way here and on the footer badges — an in-progress SOC 2 is useful information, and claiming it as finished is not.

  • India's Digital Personal Data Protection Act — consent capture, purpose limitation, and deletion on request.
  • GDPR — for customers operating in the EU, with the standard contractual clauses in the DPA.
  • HIPAA — a BAA is available for healthcare customers on enterprise plans.
  • PCI DSS — payment details are redacted from recordings and transcripts rather than stored.
  • TRAI TSR and DLT — sender IDs and templates registered before any Indian SMS traffic runs.
  • SOC 2 Type II — in progress. We will publish the report when it is issued, and not before.

Access, and who has it

Access is role-based and scoped to a campaign. A team lead sees their own team's calls; an analyst sees aggregates without the audio unless that is granted explicitly. Every grant is logged.

Hyperdial staff do not have standing access to customer recordings. Support access is time-boxed, requires a named approver on your side, and appears in your audit log the same as any other access.

Recording announcements are configurable per region and per campaign, so a flow can meet a two-party consent requirement where one applies. Consent state travels with the contact record across channels.

  • Card numbers and CVVs are detected and redacted before the recording is written to storage.
  • Identity numbers can be redacted on the same basis, per campaign.
  • Redaction applies to the transcript as well as the audio — a redacted call is redacted everywhere.

Deleting a contact removes their recordings, transcripts, scores and CRM mirror. Deletion is a real deletion, not a hidden flag, and completes within the window stated in the DPA.

Availability and incidents

Paid plans carry a 99.9% uptime target, with the contractual terms set out in the order form. Live status is published at status.hyperdial.io.

Security incidents affecting your data are notified to your named contact within the window the DPA specifies, with what we know at the time rather than after the investigation closes.

Questions a security review always asks

Read the DPA →

Yes — the executive summary is available under NDA, and the full report to enterprise customers during procurement. Ask your account contact or write to us from the contact page.

Send us your security questionnaire

HyperDial

AI communication platform that connects your calls, learns what wins, and runs across your channels.

sales@hyperdial.io
iOSAndroidDesktop
SECURITY & COMPLIANCE
SOC 2 TYPE II GDPR COMPLIANT
Encrypted in transit and at rest, stored in region