Your clients carry compliance obligations. The platform you run their communications on should make those obligations easier to meet, not harder. Here’s how 1Stream protects your data and theirs.
Straight answers, current as of 2026. No badge we haven’t earned, no claim we can’t back with a document.
Our SOC 2 audit is underway with an independent third-party firm, covering security, availability, and confidentiality. We’ll publish attestation details here once the audit completes. For current timeline, contact our security team.
For partners whose end-clients have HIPAA obligations, a Business Associate Agreement is available through our datacenter provider. Combined with restricted access controls and audit logging, this supports healthcare-adjacent workloads.
Private cloud infrastructure in North America, the UK and Europe, and Australia and New Zealand. Pick the region that fits your clients’ latency and data-locality needs. Full map below.
We list compliance status honestly. When an audit is in progress, we say so rather than implying it’s finished. If you have a security questionnaire or a specific framework you need addressed, our security team will give you a direct answer.
Private cloud infrastructure across North America, Europe, and APAC. Pick the region that fits your clients’ data-locality and latency needs. Live status of every node at status.1stream.com.
Datacenter and point-of-presence coverage across the US and Canada, including Ashburn, Chicago, Dallas, Denver, Los Angeles, Toronto, and Vancouver.
UK and European infrastructure with dual-location redundancy, so EU partners can keep client data on European soil. Data Processing Addendum available on request.
Australian and New Zealand infrastructure for partners serving the region, keeping voice traffic and data local for latency and residency.
Direct relationships with regional tier-1 carriers, not resold transit. Lower latency, higher call quality, fewer hops.
The architecture-level controls that run under every tenant, every call, and every recording.
TLS 1.2+ for data in transit. AES-256 for data at rest. SRTP for voice media. Call recordings are encrypted in storage.
Single sign-on via Microsoft and Google. Multi-factor authentication on admin access. Role-based access control scoped per tenant.
Audit logs for admin actions, configuration changes, and data access. Available for review when your team needs an activity trail.
Each partner and each of their clients operates in a logically separated tenant. Configuration, data, and access stay scoped to the right boundary.
Stop and start recording mid-call for payment-card-friendly call flows, so card details can be captured without landing in a recording.
Regional infrastructure with redundancy built in. Real-time platform health is published publicly at status.1stream.com so you’re never guessing.
Security questionnaires, Data Processing Addendums, BAA paperwork, architecture detail for your client’s auditor. Tell us what your review needs and the security team will get back to you.
Thanks. The security team will follow up at the email you provided, typically within one business day.
A 20-minute walkthrough with the team. Bring your security questions and your clients’ compliance requirements.