AgentTech 360 is now generally available for FMOs and IMOs. Read the announcement

Security and compliance.

Insurance calls carry health information, payment details, and Medicare identifiers. AgentTech is built to protect them: encryption everywhere, role-based access scoped to your hierarchy, and SOC 2 and HIPAA programs monitored continuously through Vanta.

HIPAA compliant, powered by Vanta SOC 2, powered by Vanta

Compliance

HIPAA and SOC 2, monitored every day.

AgentTech runs its compliance program on Vanta, which continuously tests our controls, collects evidence, and alerts us the moment anything drifts. Reports and our Business Associate Agreement are available to customers and prospects under NDA.

Security controls

The measures that protect your business and your customers' information.

Encryption everywhere

TLS 1.2+ in transit and AES-256 at rest for recordings, transcripts, and CRM data. Keys are managed and rotated by the platform.

Role-based access

Least-privilege roles scoped to the agency hierarchy. An agency administrator sees their downline; an agent sees their own work.

Authentication

Multi-factor authentication, single sign-on for agencies, session controls, and IP allow-lists for supervisor tools.

Audit trail

Every login, recording playback, export, and configuration change is logged with who, what, and when.

Data residency and retention

U.S. data centers, cross-region replication, and retention windows you set per data type.

Vulnerability management

Continuous dependency scanning, fixed patch cadence, and annual independent penetration testing.

Built for the data insurance calls carry.

Recordings, transcripts, and enrollment details are regulated data. The platform treats them that way by default.

Protected health information

  • Business Associate Agreement available for every customer
  • PHI redaction in transcripts on request
  • Recording access restricted by role and logged
  • Retention windows per data type, enforced automatically

Payment and identity data

  • Card data handled by a PCI DSS Level 1 processor; never stored on our servers
  • Medicare numbers and SSNs masked in the UI and exports
  • Tenant isolation at the database layer
  • Signed, replay-protected webhooks and scoped API keys

Availability and resilience.

A dialer that is down during AEP is a compliance problem too. The platform is designed to stay up and to recover fast.

  • Redundant voice and SMS carriers with automatic failover.
  • Encrypted backups replicated across regions and tested on a schedule.
  • Zero-downtime deploys and a public status page.
  • Incident response with customer notification commitments.

Program at a glance

SOC 2
Security, availability, and confidentiality controls monitored through Vanta.
HIPAA
Safeguards for PHI and a BAA for every customer that needs one.
Annual
Independent penetration testing, findings tracked to closure.

FAQs

Security questions

Is AgentTech HIPAA compliant?

Yes. AgentTech operates a HIPAA program with administrative, physical, and technical safeguards for protected health information, and we sign Business Associate Agreements with agencies that handle PHI. Controls are monitored continuously through Vanta.

What about SOC 2?

Our SOC 2 program covers security, availability, and confidentiality. Evidence collection and control monitoring run continuously through Vanta, and the current report is available to customers and prospects under NDA.

Where is data stored?

In U.S. data centers. Recordings, transcripts, and CRM data are encrypted at rest and replicated across regions. Customers can set retention periods per data type.

Who can access call recordings?

Only users your administrators grant the permission to. Access is role-based, scoped to the agency hierarchy, and every playback and download is written to the audit trail.

How do you handle vulnerability management?

Dependencies are scanned continuously, infrastructure is patched on a fixed cadence, and independent penetration tests run at least annually. Findings are tracked to closure in Vanta.

How do I report a security issue?

Email security@agenttech.io. We acknowledge reports within one business day.

Something else? Contact us

Need the paperwork?

Request our SOC 2 report, HIPAA documentation, BAA, or a completed security questionnaire.