Security & Compliance

Built for the calls where it matters.

Healthcare, legal, and any business that cares about caller privacy deserve a clear picture of how their data is handled. Here it is — in plain English.

  • HIPAA-compliant infrastructure

    Our infrastructure is built to support HIPAA-compliance for healthcare customers. We sign Business Associate Agreements (BAAs) with healthcare practices. Patient information captured on calls is encrypted at rest and in transit, with full audit logging on every access.

  • SOC 2 Type II controls

    We operate under SOC 2 Type II control mappings — access management, change management, encryption, incident response, vendor management. Documentation is available under NDA during the procurement evaluation.

  • US-East AWS hosting

    All call data, transcripts, and recordings live in US-East AWS regions under SOC 2 Type II infrastructure. No data leaves the US. No data sent to foreign-hosted LLMs.

  • Attorney-client privilege

    For law firm customers, calls are flagged and stored with retention rules that align with attorney-client privilege protocols. Privileged-communication handling is walked through during onboarding.

  • Caller transparency

    When a caller directly asks "is this AI?", the agent answers honestly. You can also configure the agent to identify itself as a virtual assistant in the opening line — your call.

  • US-based, US-staffed

    Founder, infrastructure, and support all US-based. The only thing offshore is your competition's call center.

Data practices — plain English.

No 40-page legal PDF. What we collect, how long we keep it, who can see it.

What we collectCall audio, transcript, caller phone number (provided by Twilio), captured fields you configure (name, appointment time, etc.).
How long we keep itDefault retention: 90 days for call audio + transcripts. Configurable to 30, 60, 90 days, or indefinite per your data retention policy.
Who can access itYou + designated team members in your workspace. RingRouteUSA staff access requires explicit authorization for support tickets, logged in our audit trail.
EncryptionTLS 1.3 in transit. AES-256 at rest. Healthcare audio additionally encrypted with per-tenant keys.
Third-party sharingNone. We do not sell, share, or use your call data for model training. Period.
Compliance supportBAA available for healthcare. Custom data processing agreements available on Enterprise. Standard DPA covers most use cases.
What we DON'T do
  • ×We do not sell your call data.
  • ×We do not use your call data to train shared AI models.
  • ×We do not send your call data outside the US.
  • ×We do not log into your customer accounts on your behalf.
  • ×We do not auto-respond to your customers based on our judgment — only on the script you configure.

Need a BAA, DPA, or our SOC 2 report? Reach out — we respond within hours.

Hear It Before You Buy It

Most important security control:
hear the AI first.

Before you trust any vendor with caller data, hear what their AI actually says on a call. Click the widget — no signup, no data captured.

Or book a 15-minute demo if you'd rather walk through your setup with a human first.

We value your privacy

We use essential cookies to run this site, and optional analytics (Cloudflare, cookieless) to understand traffic. You choose. See our Cookie Policy and Privacy Policy.