1Stream 1Stream
Trust Center

Security that earns the room.

Your clients carry compliance obligations. The platform you run their communications on should make those obligations easier to meet, not harder. Here’s how 1Stream protects your data and theirs.

Compliance posture

Where we stand today.

Straight answers, current as of 2026. No badge we haven’t earned, no claim we can’t back with a document.

In progress

SOC 2

Our SOC 2 audit is underway with an independent third-party firm, covering security, availability, and confidentiality. We’ll publish attestation details here once the audit completes. For current timeline, contact our security team.

Available

HIPAA BAA

For partners whose end-clients have HIPAA obligations, a Business Associate Agreement is available through our datacenter provider. Combined with restricted access controls and audit logging, this supports healthcare-adjacent workloads.

Live

Regional data residency

Private cloud infrastructure in North America, the UK and Europe, and Australia and New Zealand. Pick the region that fits your clients’ latency and data-locality needs. Full map below.

We list compliance status honestly. When an audit is in progress, we say so rather than implying it’s finished. If you have a security questionnaire or a specific framework you need addressed, our security team will give you a direct answer.

Data residency

Your data stays in your region.

Private cloud infrastructure across North America, Europe, and APAC. Pick the region that fits your clients’ data-locality and latency needs. Live status of every node at status.1stream.com.

Private cloud datacenters & POPs
North America

United States & Canada

Datacenter and point-of-presence coverage across the US and Canada, including Ashburn, Chicago, Dallas, Denver, Los Angeles, Toronto, and Vancouver.

Europe

United Kingdom & Europe

UK and European infrastructure with dual-location redundancy, so EU partners can keep client data on European soil. Data Processing Addendum available on request.

APAC

Australia & New Zealand

Australian and New Zealand infrastructure for partners serving the region, keeping voice traffic and data local for latency and residency.

Direct relationships with regional tier-1 carriers, not resold transit. Lower latency, higher call quality, fewer hops.

Security practices

How we protect your data.

The architecture-level controls that run under every tenant, every call, and every recording.

Encryption

In transit and at rest

TLS 1.2+ for data in transit. AES-256 for data at rest. SRTP for voice media. Call recordings are encrypted in storage.

Access control

SSO, MFA, and RBAC

Single sign-on via Microsoft and Google. Multi-factor authentication on admin access. Role-based access control scoped per tenant.

Audit logging

Every action, recorded

Audit logs for admin actions, configuration changes, and data access. Available for review when your team needs an activity trail.

Tenant isolation

Separation per partner

Each partner and each of their clients operates in a logically separated tenant. Configuration, data, and access stay scoped to the right boundary.

Call handling

PCI-aware recording

Stop and start recording mid-call for payment-card-friendly call flows, so card details can be captured without landing in a recording.

Resilience

Redundancy and status

Regional infrastructure with redundancy built in. Real-time platform health is published publicly at status.1stream.com so you’re never guessing.

Documentation

Need it in writing?

Security questionnaires, Data Processing Addendums, BAA paperwork, architecture detail for your client’s auditor. Tell us what your review needs and the security team will get back to you.

  • Active partners: ask your channel rep, or use the form here.
  • Prospects: use the form, or email security@1stream.com directly.
  • Security concern to report? Use the same address and flag it as security in your message.
A real person on the security team will respond, typically within one business day.

Request received.

Thanks. The security team will follow up at the email you provided, typically within one business day.

Ready when you are

See how 1Stream fits your security posture.

A 20-minute walkthrough with the team. Bring your security questions and your clients’ compliance requirements.