Environment and access
Review environment, identity, access, and security controls.
Trust and security
Find the information your security, procurement, legal, and technical teams need to evaluate CallCorp.
Review areas
Available documentation depends on your product scope, environment, and partner model. Contact CallCorp for approved security, privacy, reliability, and compliance documentation.
Review environment, identity, access, and security controls.
Review how website privacy, product data, customer responsibilities, and legal requirements are handled.
Review the 99.99% uptime SLA, standard business-hours support, 24/7 emergency on-call coverage, escalation procedures, and service requirements for your environment.
Understand how operating responsibilities differ by partner model.
Diligence path
Keep your review focused on the requirements and decisions that matter to your business.
Define the product, environment, data, and partner relationship you need to evaluate.
Identify your legal, security, privacy, reliability, and operating requirements.
Review approved documentation that addresses your requirements.
Document approvals, exceptions, responsibilities, and required follow-up.
Evidence scope
Available documentation depends on your requirements, environment, and partner model.
Review customer-owned AWS or Azure deployment options, system architecture, integrations, and data flows for your environment.
Review documentation for identity, access, data handling, and HIPAA-regulated workflows, including a BAA when applicable.
Review service commitments and partner responsibilities in the applicable agreement.
Learn more about CallCorp security, privacy, reliability, compliance, and how we protect customer data.
CallCorp uses a scoped diligence process to help partner security, procurement, legal, and technical teams evaluate the requirements that apply to a specific product, environment, data set, and partner relationship. The diligence process includes:
Define the scope: Identify the product, environment, data, and relationship being evaluated.
List the requirements: Separate security, privacy, legal, reliability, and operating requirements.
Match the evidence: Use current, approved materials that directly address each requirement.
Record the decision: Document approvals, exceptions, owners, and required follow-up.
CallCorp approaches diligence around the requirements of the specific relationship rather than relying on a generic security checklist, helping partners evaluate relevant evidence and operating responsibilities before making a decision.
The security and privacy documentation reviewed with CallCorp depends on the product scope, environment, data, and relationship being evaluated. Applicable evidence is confirmed as part of the diligence process rather than assumed to apply universally. A review may include documentation related to:
Identity and access: Evidence addressing identity, access, and applicable controls.
Data handling: Information about relevant data handling and privacy requirements.
Architecture and data flows: Documentation related to system boundaries, integrations, environments, and applicable data flows.
HIPAA-regulated workflows: Current evidence applicable to HIPAA-regulated workflows, including a Business Associate Agreement (BAA) when applicable.
Service and responsibility terms: Applicable commitments and operating responsibilities documented in the governing agreement.
CallCorp keeps diligence evidence scoped to the environment and relationship under review, helping partners make informed security and privacy decisions based on current, applicable documentation rather than generalized security claims.
Yes. CallCorp can support HIPAA-regulated contact center workflows, with the applicable environment, data handling requirements, responsibilities, and supporting documentation evaluated during the diligence process. For HIPAA-regulated use cases, the review may include:
Environment and data: Identify the systems, data, and workflows subject to HIPAA requirements.
Identity and access: Review applicable identity, access, and control requirements.
Data handling: Evaluate how relevant data is handled within the defined environment and workflow.
Business associate agreement: Review a BAA when applicable to the relationship.
Operating responsibilities: Establish the responsibilities of CallCorp, the partner, and other parties involved in the workflow.
CallCorp evaluates HIPAA-regulated workflows against the specific deployment and partner relationship, helping partners establish the appropriate environment, documentation, and operating boundaries for the use case.
CallCorp supports contact center reliability through defined service commitments, support resources, and escalation processes appropriate to the environment and relationship under review. CallCorp service considerations include:
99.99% uptime SLA: Review the availability commitment that applies to the environment in scope.
24/7 support: Access emergency on-call support engineers 24/7 for issues that require assistance outside normal support hours.
Escalation path: Define how service issues are escalated and managed.
Applicable commitments: Confirm specific reliability and service obligations in the governing agreement.
CallCorp combines a 99.99% uptime SLA with standard business-hours support and 24/7 emergency on-call support, along with a diligence process that allows partners to validate the service commitments applicable to their environment before bringing CallCorp contact center technology to their customers.
CallCorp supports customer-owned Amazon Web Services (AWS) or Microsoft Azure deployment options, allowing architecture and infrastructure requirements to be evaluated around the environment and partner relationship in scope. A technical diligence review may consider:
Cloud environment: Evaluate applicable customer-owned AWS or Azure deployment options.
Architecture: Review the architecture and system boundaries relevant to the deployment.
Integrations: Identify connected systems and integration requirements.
Data flows: Document how applicable data moves between systems and environments.
Operating boundaries: Define responsibilities across CallCorp, the partner, customer, and applicable technology providers.
CallCorp provides a configurable contact center foundation that can be evaluated within customer-owned AWS or Azure environments, giving partners greater visibility into architecture, integrations, data flows, and operating responsibilities before deployment.
Security, data, and operational responsibilities can vary based on the CallCorp partner model, deployment environment, customer requirements, and scope of the relationship. These boundaries should be defined during diligence and confirmed in the applicable governing agreement. The review should establish:
Environment responsibilities: Identify which parties own and operate the infrastructure and systems in scope.
Data responsibilities: Define applicable data handling and privacy responsibilities.
Security responsibilities: Establish responsibility for identity, access, controls, and other relevant security requirements.
Service responsibilities: Clarify support, escalation, reliability, and operating obligations.
Partner responsibilities: Document how responsibilities change based on the selected partner model and operating role.
CallCorp uses the diligence process to make these boundaries explicit, helping partners understand what they own, what CallCorp supports, and what commitments apply before taking the contact center solution to their customers.
CallCorp approaches AI security by evaluating how customer data is accessed, processed, stored, and shared within each AI-enabled workflow. Because AI technologies, integrations, and customer environments can vary, security and data requirements should be evaluated for the specific AI provider, use case, deployment, and data flow. Key AI security considerations include:
AI provider: Evaluate the AI technology and provider used within the customer workflow.
Data access: Identify what customer data the AI service can access and what permissions are required.
Data flow: Understand how information moves between the CallCorp platform, customer systems, and AI services.
Data handling: Evaluate applicable processing, storage, retention, privacy, and data sovereignty requirements.
Deployment requirements: Determine how the AI integration fits within the customer's technology and security environment.
Responsibility boundaries: Define the security, data, and operating responsibilities of CallCorp, the partner, customer, and applicable AI providers.
CallCorp supports extensible integrations and can work with approved AI technologies based on the customer environment and use case. The specific security, privacy, data sovereignty, deployment, and responsibility requirements depend on the AI technology and customer configuration.
Tell us what your team needs to evaluate, and we'll help you identify the relevant information and documentation.