How A1iO approaches telemarketing law, messaging regulation, data protection and platform security, plus the binding documents that govern the service.
AI voices are treated as 'artificial voice' under the TCPA. The platform enforces prior express written consent attestation at import, national + internal DNC scrubbing, 8am–9pm recipient-local calling hours, and AI disclosure at call start — on every plan.
Recording consent
Per-state two-party consent handling (e.g., California, Florida): agents announce recording where required, and recording can be disabled per campaign or per state.
A2P messaging (SMS add-on)
10DLC brand and campaign registration for every tenant, automatic STOP/START/HELP handling, quiet-hours enforcement, and separate SMS consent tracking.
Caller identity
STIR/SHAKEN attestation A on all numbers, carrier registration, daily spam-reputation monitoring and automatic number rotation and warm-up.
SECURITY & DATA PROTECTION
Enterprise-grade by default.
SOC 2 Type II
Independently audited controls over security, availability and confidentiality. Report available under NDA.
GDPR & CCPA/CPRA
DPA with SCCs available; data-subject request handling within 30 days; regional processing pinning on enterprise plans.
Encryption & access
TLS 1.2+ in transit, AES-256 at rest, role-based access with full audit logging, SSO on Agency/Enterprise.
Data isolation
Row-level tenant isolation; recordings and transcripts never train foundation models; configurable retention with immediate, propagated deletion.
HIPAA (optional)
BAA available as a flat add-on on Scale and above for healthcare use cases.
Responsible AI disclosure
Agents identify as AI, hand off to humans on request, and never fabricate pricing or policy — answers ground to your knowledge base.
Need a DPA, BAA or the SOC 2 report?
Our legal team turns standard requests around within two business days.