Security & Compliance

Secure & compliant, by design.

Captiwate is SOC 2 Type II and ISO 27001 certified. Calls are browser-to-browser, your data is encrypted in transit, and you always keep the right to control and remove it — as detailed in our privacy policy.

AICPA SOC 2 Type II certification badge
SOC 2 Type II
Independently audited,
on an ongoing basis
ISO 27001 certification badge
ISO 27001
Information security
management standard
Calls are browser-to-browser
yoursite.com/pricing
?
Visitor
live on your website
companyintentchat
Encrypted in transit · TLS
Your CRM
HubSpot · Salesforce
Contact created
Call logged
SOC 2 Type II
ISO 27001
GDPR
CCPA

Certifications & compliance

Our security controls are independently audited on an ongoing basis.

AICPA SOC 2 Type II certification badge

SOC 2 Type II Certified

Captiwate is SOC 2 Type II certified. Our security controls are independently audited on an ongoing basis.

ISO 27001 certification badge

ISO 27001 Certified

Captiwate is ISO 27001 certified — the international standard for information security management.

Annual Third-Party Penetration Testing

Independent security experts perform penetration tests of Captiwate every year, and all findings are remediated.

General Data Protection Regulation

Our founders are in the EU, meaning that we take pride in ensuring that our services are compliant with GDPR regulations.

California Consumer Privacy Act

Captiwate’s policies and processes adhere to the CCPA.

Secure Hosting Environment

Our hosting providers are SOC 1, 2, 3 & ISO 27001, 27017, 27018 compliant.

How we handle your data

Browser-to-browser calls

Captiwate calls are browser-to-browser. The whole system was designed to respect your privacy and security.

Industry-standard encryption

Your data is protected with industry-standard encryption and access controls.

You control your data

You have the right to control and remove your data, as detailed in our privacy policy.

Read the privacy policy →

Security questions, answered

Is Captiwate GDPR / CCPA compliant?

Yes. Captiwate is SOC 2 Type II and ISO 27001 certified, and we fully comply with GDPR and CCPA. Additionally, we offer customizable data privacy options to meet the specific needs of your customers.

Is Captiwate SOC 2 and ISO 27001 certified?

Yes. Captiwate is SOC 2 Type II and ISO 27001 certified — our security controls are independently audited to the highest industry standards.

Are Captiwate calls secure?

Captiwate calls are browser-to-browser, and our system was designed to respect your privacy and security.

Is Captiwate penetration tested?

Yes. Independent security experts perform penetration tests of Captiwate every year, and all findings are remediated.

Where is Captiwate hosted?

Captiwate runs in a secure hosting environment — our hosting providers are SOC 1, 2, 3 & ISO 27001, 27017, 27018 compliant.

Can I remove my data?

Yes. You have a right to control and remove your data, as it is detailed in our privacy policy.

Talk to us about security

See Captiwate on your own website and get every security question answered — or dig into the details in our Trust Center.