SignalWire · Trust Center

Signalwire Trust Center

Trust center

SignalWire maintains a public trust center documenting SOC 2 Type II, PCI DSS, and HIPAA compliance.

CompanyCommunicationsCPaaSVoiceMessagingSMSVideoWebRTCSIPTelephonyFaxAI AgentsConversational AIContact Center
Trust center:

Certifications & Compliance

SOC 2 Type IIPCI DSSHIPAA

Source

Trust Center

Raw ↑
generated: '2026-08-27'
method: searched
source: https://signalwire.com/technology/trust-center (302 -> https://compliance.signalwire.com,
  HTTP 200), https://signalwire.com/llms.txt, https://signalwire.com/docs/platform/compliance
trust_center:
  exists: true
  url: https://compliance.signalwire.com
  linked_from: https://signalwire.com/technology/trust-center
  platform: Vanta Trust Report
  http_status: 200
  checked: '2026-08-27'
  machine_readable: false
  machine_readable_note: >-
    The trust report page is fully client-rendered by Vanta (assets.vanta.com trust-report bundle)
    and serves no server-rendered certification text. The certifications below are therefore taken
    from SignalWire's OWN llms.txt at https://signalwire.com/llms.txt, which states them as fact for
    AI consumers, rather than scraped from the JS shell. The Vanta trust report itself was not
    parsed and its evidence documents were not requested.
certifications:
- name: SOC 2 Type II
  status: certified
  source: https://signalwire.com/llms.txt
- name: PCI DSS
  status: certified
  source: https://signalwire.com/llms.txt
- name: HIPAA
  status: eligible
  detail: HIPAA-eligible with Business Associate Agreements (BAAs) available to all customers,
    covering voice, AI, SMS, video and fax under one agreement.
  source: https://signalwire.com/llms.txt
  product_page: https://signalwire.com/products/baa-hipaa-compliance
compliance_guidance:
  docs: https://signalwire.com/docs/platform/compliance
  http_status: 200
  topics:
  - name: HIPAA
    url: https://signalwire.com/docs/platform/compliance/hipaa
    note: Technical controls for protecting PHI across the call lifecycle in voice AI (74KB guide).
  - name: TCPA
    url: https://signalwire.com/docs/platform/compliance/tcpa
    note: Consent gating, AI disclosure, calling-hour rules and opt-out handling for outbound voice AI.
  disclaimer: >-
    SignalWire states these guides are technical guidance and not legal advice, and that compliance
    is a shared responsibility between SignalWire, the customer, and their implementation choices.
telecom_compliance:
  - name: A2P 10DLC / Campaign Registry (TCR)
    surface: 12 REST operations across Campaign Registry Brands, Campaigns and Phone Number
      Assignments in openapi/signalwire-rest-openapi.yml
  - name: STIR/SHAKEN
    evidence: SignalWire maintains libstirshaken, a C library implementing STIR/SHAKEN STI-SP AS/VS
      and STI-CA (https://github.com/signalwire/libstirshaken)
  - name: E911
    surface: 5 REST operations for E911 Addresses
  - name: Verified Caller ID
    surface: 7 REST operations

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/signalwire-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.