Security & HIPAA
How Callgentic protects the data our agents handle, and how healthcare projects that involve protected health information run.
Infrastructure
- Our services run on Amazon Web Services in the United States (Ohio) by default, with India (Mumbai) available for customers who need it.
- The servers accept web traffic only over HTTPS. Phone-system traffic is accepted only from our carriers' published addresses.
- There are no password logins to our servers and no open remote-shell port. Administrators reach servers through AWS Systems Manager with named, audited access.
- Servers require the hardened AWS instance metadata service (IMDSv2), and AWS access uses instance roles rather than stored keys.
Encryption
- In transit: TLS for web traffic, APIs and webhooks.
- At rest: server disks and backup storage are encrypted (AES-256).
- Backups: encrypted daily disk snapshots and nightly database copies, kept for a limited period and then deleted automatically.
Access and secrets
- Access to customer data is limited to the people who need it to run and support the service.
- Service credentials are kept out of source code, in files readable only by the service itself.
- Each internal function gets only the permissions it needs. For example, the function that forwards our email can read one storage bucket and send email, nothing more.
Application safeguards
- Requests from carriers and messaging platforms are verified by their signatures before we act on them.
- Public endpoints are rate limited, and forms reject automated abuse.
- Callers are verified before an agent shares personal information, using factors the customer chooses, because caller ID can be faked.
- Agents disclose that they are AI, confirm actions only after the system has completed them, and hand off to a person when set up to do so.
- Every agent is tested with scripted calls, including interruptions and difficult cases, before it takes real calls.
Incidents
We monitor our services and have an incident response process. If a security incident affects customer data, we notify affected customers without undue delay and within 72 hours of confirming it, as our Data Processing Addendum commits.
HIPAA and healthcare
- Callgentic has signed a Business Associate Addendum with Amazon Web Services.
- We sign a Business Associate Agreement with each healthcare customer before any protected health information (PHI) reaches our services.
- For those projects, PHI is processed only by AWS services that AWS lists as HIPAA eligible and by other providers with whom a business associate agreement is in place. We configure the agent, its AI models, speech services and storage accordingly.
- We apply the minimum-necessary standard: agents collect only the information the workflow needs.
- Without a signed Business Associate Agreement, customers must not send PHI to our services.
Certifications
Callgentic does not currently hold SOC 2 or ISO 27001 certification. Amazon Web Services, which hosts our services, holds both, and its reports are available through AWS Artifact. We answer security questionnaires from customers and prospects.
Report a vulnerability
If you believe you have found a security issue, email info@callgentic.com with the subject "Security". Please give us reasonable time to fix it before disclosing it, and do not access other people's data or disrupt the service while testing. We will acknowledge your report and keep you updated.