Security & Compliance
A high-level overview of how we protect the client and customer data we handle.
1. Overview
At Beyond The Call Inc. ("We", "Beyond The Call", or the "Company"), we respect the privacy of our clients and their customers. Keeping the data we handle protected at all times is our highest priority. This document provides a high-level overview of the security practices we have in place to achieve that. Have questions or feedback? Reach out to us at [email protected].
2. Dedicated security team
Our security team is made up of specialists focused on the reliability and protection of our organization. They have led the design and build of secure, internet-facing systems at companies ranging from startups to large public organizations. Our team is trained in incident response and root cause analysis and is on call 24/7/365.
3. Infrastructure and security protection
All of our services run in the cloud. We do not host server software, DNS, or data-hosting servers on our own premises. We monitor and protect our network using:
- Internal access and authentication controls.
- A stateful packet inspection firewall that monitors and controls all network traffic.
- Virtual LAN (VLAN) segmentation.
- External log archiving with gap and throttle monitoring to surface security events.
- Multiple fiber uplinks to remove single points of failure and to provide encrypted remote connectivity for agents working abroad.
4. Data encryption
All network connectivity meets NIST and PCI guidance. We use strong Perfect Forward Secrecy (PFS) ciphers and algorithm preferences for both client and server endpoints. All data sent to or from our infrastructure is encrypted in transit using Transport Layer Security (TLS), with a minimum version of 1.2.
5. Encryption at rest
All user data, including passwords, is encrypted at rest using proven, computationally expensive algorithms in the database layer, and is accessed through an encrypted database wrapper to help prevent exposure of personal information through database vulnerabilities.
6. Data retention and removal
We retain the data we handle only as long as needed to deliver our services and in line with our client agreements. When it is no longer required, data is scrubbed and removed from our systems. Users may request removal of their data by contacting support. You can read more in our Privacy Policy.
7. Business continuity and disaster recovery
We back up all critical assets and regularly test restoring those backups to ensure fast recovery in the event of a disaster. All backups are encrypted.
8. Network security monitoring
We use a security monitoring solution for visibility into our application security, to identify attacks, and to respond quickly. We monitor exceptions and logs and detect anomalies in our applications, collect and store logs to provide an audit trail of activity, and send notifications on critical events so we can remediate quickly.
9. Responsible disclosure
We support responsible disclosure. If you believe you have found a vulnerability, please avoid automated testing, only perform security testing with your own data, and do not disclose any details publicly until we have resolved the issue. You can report vulnerabilities by contacting [email protected] with a proof of concept. We will respond as quickly as possible and will not pursue legal action against researchers who follow these rules.
10. User protection
Two-factor authentication
We use two-factor authentication for accounts and logins wherever possible to protect our clients and agents.
Account takeover protection
We help protect against breaches by monitoring and blocking brute-force attacks at the network level.
Role-based access control
We use role-based access control (RBAC) where possible to define users, roles, and permissions.
Suspicious user behavior monitoring
We monitor for suspicious network behavior and react quickly to prevent account takeovers. This also helps protect against data theft by blocking credential-stuffing and brute-force attacks based on behavior analysis.
11. Compliance
HIPAA
We offer HIPAA and Business Associate Agreements (BAAs) to enterprise clients that need to meet HIPAA requirements, and we operate HIPAA-ready environments where an engagement calls for it.
International data transfers
For personal data transferred between the EU or Switzerland and the United States, we handle transfers in line with the applicable data protection frameworks and safeguards. Contact us for more details.
General Data Protection Regulation (GDPR)
We align our practices with the General Data Protection Regulation (GDPR), which protects the personal information of EU residents and gives them more control over their personal data. Contact us for details on how we support GDPR compliance.
12. Payment information
Payment processing is handled by PCI-compliant providers (such as Bill.com via FirstData and QuickBooks, certified as PCI Level 1 service providers). We do not collect or store payment card information ourselves and are therefore not subject to PCI obligations for card data.
13. Employee access
Our internal procedures restrict any employee or administrator from gaining access to user data, with limited exceptions for customer support. All employees sign a non-disclosure and confidentiality agreement to protect our clients' sensitive information.