8x8 · Trust Center

8X8 Trust Center

Trust center

8x8 maintains a public trust center documenting SOC 2 Type II, ISO 27001:2022, ISO 27017:2015, ISO 27018:2019, CSA Cyber Trust Certificate, HIPAA, and Cyber Essentials Plus (CE+) compliance.

TelecommunicationsUnited StatesCPaaSUCaaSCCaaSContact CenterMessagingSMSVoiceVideoIdentity VerificationWebhooksCloud Communications
Trust center: https://www.8x8.com/why-8x8/security-and-compliance

Certifications & Compliance

SOC 2 Type IIISO 27001:2022ISO 27017:2015ISO 27018:2019CSA Cyber Trust CertificateHIPAACyber Essentials Plus (CE+)

Source

Trust Center

Raw ↑
generated: '2026-07-25'
method: searched
probe: true
url: https://www.8x8.com/why-8x8/security-and-compliance
url_status: 429
url_status_note: >-
  www.8x8.com is fronted by a Vercel security checkpoint that returns 429 to automated
  clients. The page is real and is the canonical 8x8 security-and-compliance destination;
  the machine-readable evidence below was taken from the API-platform mirror at
  cpaas.8x8.com/en/security/ (HTTP 200), which 8x8 publishes for the same programme.

mirrors:
- url: https://cpaas.8x8.com/en/security/
  name: 8x8 CPaaS Security
  status: 200
- url: https://www.8x8.com/products/apis/security
  name: Security for 8x8 Communication APIs
  status: 429
- url: https://developer.8x8.com/connect/docs/security-1
  name: Security (Connect developer docs)
  status: 200

certifications:
- name: SOC 2 Type II
  detail: Audit certification — "8x8 cybersecurity controls are designed sufficiently and
    operated effectively throughout the testing periods."
- name: ISO 27001:2022
  detail: Information security management system globally certified as compliant with
    ISO 27001:2022, incorporating the ISO 27017:2015 and ISO 27018:2019 control sets.
  auditor: Alcumus ISOQAR
- name: ISO 27017:2015
  detail: Cloud security control set, incorporated into the ISO 27001 certification.
- name: ISO 27018:2019
  detail: Cloud PII protection control set, incorporated into the ISO 27001 certification.
- name: CSA Cyber Trust Certificate
  detail: Awarded by the Cyber Security Agency of Singapore; 8x8 states it was one of the
    first companies to receive it.
- name: HIPAA
  detail: HIPAA compliance is claimed for the 8x8 platform.
- name: Cyber Essentials Plus (CE+)
  detail: UK Cyber Essentials Plus certificate.

compliance_documents:
- url: https://cdn.8x8.com/files/mfagl40e/production/dac2a28d292e45a1bc70eb09e381d479bda50f75.pdf
  name: 8x8 Communication APIs Security Overview Essentials
- url: https://cdn.8x8.com/files/mfagl40e/production/31dda989717998a16d354d38dee9fc8c9649c1f9.pdf
  name: Security and Compliance Assurance Packet (prepared by the 8x8 Security Team)

not_claimed:
- PCI DSS
- FedRAMP
- CSA STAR (registry listing)
- FIPS 140
not_claimed_note: Absence here means no published claim was found on 8x8's public security
  pages — it is recorded as data, not asserted as a failure.

platform_security_features:
- Two-factor authentication (Authenticator app or SMS OTP) on the 8x8 Connect portal
- SAML single sign-on for 8x8 Connect
- Minimum TLS 1.3 enforcement on the API platform (HTTP 426 + Upgrade: TLS/1.3)
- PII deletion API (Remove Personally Identifiable Information) for messaging records
- Client-IP rate limiting as an SMS AIT / pumping mitigation

evidence:
- source: https://cpaas.8x8.com/en/security/
  status: 200
  keywords: [SOC2 Type II, ISO 27001:2022, ISO 27017, ISO 27018, CSA Cyber Trust, HackerOne]