What security certifications should a cloud contact center have?
The baseline certifications to look for are PCI DSS Level 1 (for handling payment card data), SOC 2 Type II (for independently audited security, availability, and confidentiality controls), and ideally SOC 3 (a public summary of the SOC 2 audit). ISO 27001 is common in enterprise contexts. These indicate the vendor has been independently assessed against recognized security standards — not just self-certified. The presence of these certifications is a necessary starting point, not a sufficient end point for your evaluation.
What PCI DSS actually means in a contact center
PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements for any organization that handles cardholder data — credit card numbers, expiration dates, CVV codes, and related information. In a contact center context, this matters when agents take payments over the phone or handle billing disputes where card data is discussed or keyed in.
PCI DSS Level 1 is the highest compliance tier. It requires an annual on-site audit by a Qualified Security Assessor (QSA) — not a self-assessment form. Vendors claiming PCI compliance but not specifying Level 1 may have completed a self-assessment questionnaire, which has far less independent rigor.
What PCI DSS Level 1 compliance means in practice for a contact center: the vendor's infrastructure meets requirements for network segmentation, access controls, encryption of cardholder data at rest and in transit, logging and monitoring, and vulnerability management. It doesn't automatically mean that everything your agents do with card data is PCI-compliant — how your scripting, recording, and agent procedures are configured matters too.
What SOC 2 Type II means
A SOC 2 Type II report is produced by an independent CPA firm that has audited a vendor's controls against the AICPA Trust Services Criteria — typically covering security, availability, processing integrity, confidentiality, and privacy. Type II means the audit covered a period of time (usually 6–12 months), not just a point-in-time assessment. That's significantly more meaningful than a Type I audit.
When evaluating a vendor's SOC 2 report, the key question isn't just whether they have one — it's whether they can share the full report (or a summary), and whether there are any exceptions or qualifications in the auditor's findings. A clean SOC 2 report is a signal. The details are in the exceptions.
SOC 3 is a public-facing version of the SOC 2 summary that vendors can publish without confidential detail. Its existence signals that the vendor has completed a SOC 2 audit — but for due diligence, the SOC 2 report itself is what you want to see.
Beyond certifications: the questions that reveal actual security posture
How is call recording data stored and encrypted?
Call recordings contain sensitive information — customer PII, payment data, escalation content — and they accumulate at significant volume. Ask specifically: What encryption standard is used for recordings at rest? Where are recordings stored (the vendor's own infrastructure, or a sub-processor's)? What is the retention period and is it configurable? Who within the vendor's organization has access to recordings, and under what circumstances?
What does PII redaction cover?
For contact centers where sensitive data is verbalized during calls — card numbers, social security numbers, health information — recording that data creates a compliance obligation. PII redaction capability means the recording system can detect and mute those portions of the audio automatically, so recordings exist for quality and compliance purposes without storing the raw sensitive data. Verify what data types are covered and how the redaction is implemented (keyword-based, NLP-based, manual review).
How is remote agent access secured?
In hybrid and remote environments, agents connect to the contact center platform from home networks, public Wi-Fi, and personal devices. Ask the vendor: Is MFA (multi-factor authentication) required for agent login? Is there session timeout and automatic lock? Are there controls on whether agents can download call recordings or customer data locally? Is there an audit trail of what data was accessed by which agent?
What is the breach notification process?
Vendors won't volunteer this information in a sales conversation, but it matters. In the event of a data breach affecting your customer records, what is the vendor's contractual obligation for notification timing? Do they carry cyber liability insurance? Who is the designated security contact, and how quickly can you reach them?
What infrastructure does it run on, and what does geo-redundancy mean for them?
A vendor claiming geo-redundant infrastructure might mean two data centers in the same city — which doesn't protect against a regional outage. Ask specifically: which cloud provider and which regions? What is the failover time if a primary region goes down? What is the documented RTO (recovery time objective) and RPO (recovery point objective)?
The operational security dimension
Infrastructure security is only part of the picture. Contact center security also includes the operational controls that govern what agents can do with the systems they access — and what supervisors and administrators can see and configure.
Role-based access control matters: agents shouldn't have admin access to routing configuration. Supervisors shouldn't be able to delete call recordings. IT administrators shouldn't necessarily have access to every client's call data in a multi-tenant environment. How the platform implements role separation is a practical security question as important as certification status.
SA Hosted security at a glance
AWS geo-redundant infrastructure. PCI DSS Level 1 certified. SOC 2/3 certified. Encryption in transit and at rest. Call recording with PII redaction. Role-based access across all user tiers.
See Security & Reliability Talk to SA Hosted