CallRail · Trust Center

Callrail Trust Center

Trust center

CallRail runs a Conveyor-hosted Trust Center at trust.callrail.com and a public Security & Compliance page at callrail.com/security that names each certification and links a PDF or certificate for it.

CallRail maintains a public trust center documenting ISO 42001, SOC 2 Type II, HIPAA/HITECH, PCI, GDPR, and CCPA compliance.

Call TrackingConversation IntelligenceMarketing AttributionLead TrackingTelephonyAnalyticsForm Tracking
Trust center: https://trust.callrail.com/

Certifications & Compliance

ISO 42001SOC 2 Type IIHIPAA/HITECHPCIGDPRCCPA

Source

Trust Center

Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://trust.callrail.com/
url: https://trust.callrail.com/
compliance_page: https://www.callrail.com/security
description: >-
  CallRail runs a Conveyor-hosted Trust Center at trust.callrail.com and a public
  Security & Compliance page at callrail.com/security that names each certification and links a
  PDF or certificate for it.
certifications:
  - name: ISO 42001
    detail: >-
      International standard for AI Management Systems. CallRail states it is the first in the lead
      intelligence industry to achieve it.
    evidence_url: https://cdn.mediavalet.com/usva/callrail/5G5pOJO060Kj1FZFrhaqqw/Qs9xhIoxu0KoZiSB23qBdg/Original/CallRail%20-%20ISO%2042001-2023%20Certificate.pdf
  - name: SOC 2 Type II
    detail: AICPA Service Organization Control 2, Type II.
    evidence_url: https://www.callrail.com/usva/callrail/8ixJQwzZlkuBizzhSK09kA/jUgxdIpx0USV27Zbp84xkw/Original/SOC_2_compliance.pdf
  - name: HIPAA/HITECH
    detail: >-
      End-to-end solution for health care providers and the agencies serving them; the v3 API
      exposes a `hipaa_account` flag on the account object and a HIPAA-specific variant of the call
      recording endpoint.
    evidence_url: https://www.callrail.com/usva/callrail/4g3exyu5k0GqpErYVw2qpg/AEcW9ddKukqZCoAeoBAFrQ/Original/HIPAA_compliance.pdf
  - name: PCI
    detail: PII redaction feature to reduce liability when payment information is spoken on a recorded or transcribed call.
    evidence_url: https://www.callrail.com/usva/callrail/pkVFEXTZgEyFhuY16rOBtA/G3wN0kTl3k6mHn34DeWtzw/Original/PCI.pdf
  - name: GDPR
    detail: EU General Data Protection Regulation posture.
    evidence_url: https://www.callrail.com/usva/callrail/23FeJHMNREant2JpS7j7PA/hSMAt6h8BkigopJUkJ7-0g/Original/GDPR.pdf
  - name: CCPA
    detail: California Consumer Privacy Act posture.
    evidence_url: https://www.callrail.com/usva/callrail/3YcDpEmtd0u5mvzzU18CTA/dfkiXN7acU6c28AU_GKZBQ/Original/CCPA.pdf
responsible_ai:
  url: https://www.callrail.com/security/ai
  note: Published AI principles page (transparency, ethical innovation, security), tied to the ISO 42001 certification.
vulnerability_disclosure:
  url: https://www.callrail.com/security/disclosure
  detail: security/callrail-vulnerability-disclosure.yml
subprocessors:
  published: true
  count: 12
  source: https://trust.callrail.com/
  last_updated: '2026-02-03'
evidence:
  - source: https://www.callrail.com/security
    http_status: 200
    fetched: '2026-08-14'
    keywords: [ISO 42001, SOC 2 (Type II), HIPAA/HITECH, PCI, GDPR, CCPA, Vulnerability Disclosure Program]
  - source: https://trust.callrail.com/
    http_status: 200
    fetched: '2026-08-14'
    keywords: [trust center, soc2-type-2, iso-42001, hipaa, pci]
x-corrections:
  - date: '2026-08-14'
    note: >-
      Replaced the certification list written by probe-security-programs.py on the same day, which
      recorded SOC 2, ISO 27001, ISO 27017, ISO 27018, HIPAA, FedRAMP and GDPR. Those were FALSE
      POSITIVES: trust.callrail.com is a Conveyor trust center whose page payload embeds the
      certification arrays of OTHER vendors (CallRail's subprocessors — Salesforce, AWS, Zendesk
      and others), and the keyword scan picked them up. CallRail's own certification array in that
      same payload is ["hipaa","soc2-type-2","pci","iso-42001"], which matches its public
      Security & Compliance page exactly. CallRail holds no ISO 27001/27017/27018 and no FedRAMP
      authorization that it publishes.