Security & Data Handling
What we actually do, described plainly enough that you can assess it against your own requirements — and an explicit list of what we do not claim.
We do not hold SOC 2, ISO 27001, HIPAA or PCI DSS certification, and we will not imply otherwise. If your business requires a certified provider for regulatory or contractual reasons, that is a legitimate requirement and you should choose one. This page describes the controls we operate so you can make that judgement with real information rather than marketing language.
The principle everything else follows from
Agents work inside your systems, using accounts you create, with permissions you set and access you can revoke at any moment without asking us. We do not ask you to migrate data to a platform of ours, and for most campaigns your customer data never leaves your control in the first place.
That structure does more for your security position than any certificate we could buy, because it means the ultimate control stays with the party that has the most to lose.
Least-privilege access
- Agents receive the minimum permissions the task genuinely requires — a scoped support or agent role, not administrative access.
- Where your system supports it, destructive permissions (bulk delete, data export, user management) are excluded from agent roles.
- Access is requested per system and per function, not granted wholesale at the start of a campaign.
- If we do not need a system to do the work, we do not ask for it.
Client-controlled accounts
- You create the accounts. We do not create accounts in your systems on your behalf.
- Individual named accounts per agent wherever your platform supports it, so activity is attributable to a person.
- Shared or generic logins are avoided; where a system genuinely cannot support individual accounts, we will tell you and you can decide whether that is acceptable.
- You can audit, suspend or revoke any account at any time without contacting us first.
Password and authentication policy
- Credentials are not shared between agents.
- Credentials are not sent over unencrypted channels or stored in plain text documents.
- Multi-factor authentication is used wherever your system offers it — and we will ask you to enable it if it is available and switched off.
- Passwords are changed when an agent leaves the campaign, in addition to the account being disabled.
Role-based access, where supported
Most CRM, helpdesk and chat platforms support role-based permissions. Where yours does, we work with you to define an agent role that grants exactly the functions the campaign requires and nothing else. Where a platform only offers all-or-nothing access, we will say so explicitly during scoping rather than quietly accepting admin rights.
Confidentiality
- Confidentiality obligations form part of the engagement agreement and extend to the agents working your campaign.
- Campaign material, scripts, customer data and commercial information are not used for, or discussed with, any other client.
- Agents are instructed not to retain copies of client data outside the client's systems.
- Where you have specific confidentiality requirements — a professional obligation, a client contract of your own — raise them during scoping so they can be addressed in the agreement.
Device and workspace policy
- Agents work from a workspace suitable for confidential conversations, not a public or shared environment where calls can be overheard.
- Screens are locked when unattended.
- Client data is not copied to personal storage, personal email or personal messaging.
- Where a campaign requires stricter device controls than our standard policy, that has to be agreed and priced during scoping — it is not something we can retrofit silently.
Screen access and recording
Some clients require session recording or screen monitoring on their systems. Where your platform provides it, it is your tool and your decision, and we will work within it. Where you need it and your platform does not provide it, tell us during scoping so we can be honest about what is achievable rather than agreeing to something we cannot evidence.
Data handling
- Data is accessed for the purpose of the campaign and no other purpose.
- Data is handled inside your systems wherever the workflow allows it.
- Where a file must be exchanged — a lead list, a report — it is shared through a channel you nominate, not an arbitrary one.
- Retention of anything held outside your systems is agreed in the service agreement, along with what happens to it on termination.
Access revocation after termination
When an agent leaves your campaign, or when the engagement ends:
- We notify you of the change so you can act on your side.
- Accounts are disabled or deleted by you — because you own them, this is under your control rather than dependent on us remembering.
- Any credentials the agent held are changed.
- Any campaign material held outside your systems is dealt with as set out in the agreement.
The important point: because the accounts are yours, you never have to trust that we performed a revocation. You can verify it yourself.
Incident escalation
If something goes wrong — a suspected unauthorised access, a misdirected communication containing customer data, a lost credential — the process is:
- The agent reports it immediately rather than attempting to resolve it quietly.
- Access involved is suspended.
- You are notified without delay, with what is known at that point rather than after an internal investigation concludes.
- We support your own incident response, including any regulatory notification obligations that fall on you.
We would rather tell you about a small incident early than manage it internally and have you discover it later. Any provider who has never reported an incident to a client has either been extremely lucky or is not telling you things.
What this page does not do
It does not constitute a security certification, an audit report or a legal warranty. It is a description of operating practice. If your requirements are stricter than what is described here — and for some regulated businesses they will be — raise it during scoping. We would rather decline an engagement than accept obligations we cannot actually meet.