Compliance
- ✓Service infrastructure maintained
- ✓Production database access restricted
- ✓Remote access MFA enforced
- ✓Employee background checks performed
- ✓Security awareness training implemented
- ✓Production inventory maintained
- ✓Privacy policy established
- ✓Data retention procedures established
- ✓Privacy compliant procedures established
- ✓Data encryption utilized
- ✓Vulnerability scanning performed
- ✓Penetration testing performed annually
- ✓ Customer personally identifiable information
- ✓ Billing information
- ✕ Credit card information
- ✕ Personal health information
FAQ
Where can I find Callvix's SOC 2 report?
Request access at the top of this page. Once approved, the SOC 2 Type II report is available under Resources → Compliance.
Where can I find Callvix's Data Processing Addendum?
The DPA is listed under Resources → Privacy and does not require approval to view.
How does Callvix handle access controls and authentication?
Production access is role-based, time-boxed, and reviewed quarterly. Multi-factor authentication is required for all employee accounts with access to customer data or infrastructure.
How do I report a security vulnerability?
Email grc@callvix.example with details. We acknowledge reports within one business day.