Trust & security

Built for businesses
that can't cut corners.

SoloDial is used by medical practices, legal offices, and property managers — businesses that can't afford to mishandle a customer call, and certainly not customer data. Here's exactly how we keep yours safe.

AES-256 encryption
All data at rest and in transit
SOC 2 in progress
Report expected Q3
HIPAA-aligned configs
Available on Enterprise plans
PCI-compliant billing
Via Stripe · no card data touches our servers
Daily encrypted backups
7-day rolling retention
US data residency
Primary region: us-east-1 (Virginia)
01 · Call recording & consent

Consent-first by default.

Every voice agent can announce call recording at the start of a call — and the setting is on by default. For two-party-consent states (California, Florida, etc.) we surface the requirement in the UI so you can't accidentally ship a non-compliant agent. Recordings are stored encrypted, never shared, and purged on your schedule.

01
02 · HIPAA posture

For medical practices, specifically.

On Enterprise plans we offer HIPAA-aligned configurations with signed BAAs, disabled AI training on your data, US-only processing, 7-year retention policies, and dedicated audit logs. We're not a legal substitute for your own compliance program, but we're built to fit inside one.

02
03 · Data handling

You own your data. Always.

Transcripts, recordings, customer details — all yours. We don't train AI on your data. We don't sell it. You can export everything as JSON or delete your entire account with one click, and we guarantee purge within 30 days. We never retain anything past your delete request.

03
04 · Infrastructure

Serious infrastructure.

Hosted on AWS in US-East-1, with automated failover, read replicas, and daily encrypted backups. All secrets rotated automatically. Internal access requires 2FA and is audit-logged. We monitor uptime 24/7 and publish a public status page at status.solodial.com.

04
05 · Access & authentication

Sensible security, no friction.

Two-factor authentication on all accounts. Single sign-on available on Enterprise. Session tokens rotate on activity. Password reset via email link with single-use tokens. No plaintext passwords, ever. Admin access is role-limited and fully audited.

05
Security contact

Found something?
Tell us.

We respond to all security reports within 24 hours. Responsible disclosure gets our thanks and, on qualifying issues, a bounty.

security@solodial.com