generated: '2026-08-14' method: searched probe: true source: https://trust.callrail.com/ url: https://trust.callrail.com/ compliance_page: https://www.callrail.com/security description: >- CallRail runs a Conveyor-hosted Trust Center at trust.callrail.com and a public Security & Compliance page at callrail.com/security that names each certification and links a PDF or certificate for it. certifications: - name: ISO 42001 detail: >- International standard for AI Management Systems. CallRail states it is the first in the lead intelligence industry to achieve it. evidence_url: https://cdn.mediavalet.com/usva/callrail/5G5pOJO060Kj1FZFrhaqqw/Qs9xhIoxu0KoZiSB23qBdg/Original/CallRail%20-%20ISO%2042001-2023%20Certificate.pdf - name: SOC 2 Type II detail: AICPA Service Organization Control 2, Type II. evidence_url: https://www.callrail.com/usva/callrail/8ixJQwzZlkuBizzhSK09kA/jUgxdIpx0USV27Zbp84xkw/Original/SOC_2_compliance.pdf - name: HIPAA/HITECH detail: >- End-to-end solution for health care providers and the agencies serving them; the v3 API exposes a `hipaa_account` flag on the account object and a HIPAA-specific variant of the call recording endpoint. evidence_url: https://www.callrail.com/usva/callrail/4g3exyu5k0GqpErYVw2qpg/AEcW9ddKukqZCoAeoBAFrQ/Original/HIPAA_compliance.pdf - name: PCI detail: PII redaction feature to reduce liability when payment information is spoken on a recorded or transcribed call. evidence_url: https://www.callrail.com/usva/callrail/pkVFEXTZgEyFhuY16rOBtA/G3wN0kTl3k6mHn34DeWtzw/Original/PCI.pdf - name: GDPR detail: EU General Data Protection Regulation posture. evidence_url: https://www.callrail.com/usva/callrail/23FeJHMNREant2JpS7j7PA/hSMAt6h8BkigopJUkJ7-0g/Original/GDPR.pdf - name: CCPA detail: California Consumer Privacy Act posture. evidence_url: https://www.callrail.com/usva/callrail/3YcDpEmtd0u5mvzzU18CTA/dfkiXN7acU6c28AU_GKZBQ/Original/CCPA.pdf responsible_ai: url: https://www.callrail.com/security/ai note: Published AI principles page (transparency, ethical innovation, security), tied to the ISO 42001 certification. vulnerability_disclosure: url: https://www.callrail.com/security/disclosure detail: security/callrail-vulnerability-disclosure.yml subprocessors: published: true count: 12 source: https://trust.callrail.com/ last_updated: '2026-02-03' evidence: - source: https://www.callrail.com/security http_status: 200 fetched: '2026-08-14' keywords: [ISO 42001, SOC 2 (Type II), HIPAA/HITECH, PCI, GDPR, CCPA, Vulnerability Disclosure Program] - source: https://trust.callrail.com/ http_status: 200 fetched: '2026-08-14' keywords: [trust center, soc2-type-2, iso-42001, hipaa, pci] x-corrections: - date: '2026-08-14' note: >- Replaced the certification list written by probe-security-programs.py on the same day, which recorded SOC 2, ISO 27001, ISO 27017, ISO 27018, HIPAA, FedRAMP and GDPR. Those were FALSE POSITIVES: trust.callrail.com is a Conveyor trust center whose page payload embeds the certification arrays of OTHER vendors (CallRail's subprocessors — Salesforce, AWS, Zendesk and others), and the keyword scan picked them up. CallRail's own certification array in that same payload is ["hipaa","soc2-type-2","pci","iso-42001"], which matches its public Security & Compliance page exactly. CallRail holds no ISO 27001/27017/27018 and no FedRAMP authorization that it publishes.