Security, privacy & compliance — by design
Data sovereignty as architecture, not a toggle: your cloud, your keys, AES-256 and TLS encryption, and an immutable audit trail — governed by SSO/SAML, SCIM, and fine-grained RBAC. We publish our compliance program status rather than badges.
Built for the most regulated contact centers on earth
Arkivo is engineered so your recordings stay yours — encrypted, residency-bound, and access-controlled — while you keep the evidence trail regulators and auditors expect.
Your recordings never leave your tenant. Arkivo holds the index — you hold the data.
Sovereignty isn't a setting you toggle on — it's the architecture. Your cloud, your keys, your region, your audit trail, fully under your control.
What we can prove today
Arkivo holds no compliance attestations yet, and we don't display badges for ones we haven't earned. These are the claims we will defend line by line in a security review.
Recordings, keys, and AI inference remain in your own cloud tenant. Arkivo stores no PHI.
Underlying infrastructure runs under your own cloud provider agreements — AWS, Azure, or GCP — and that provider's attestations, not ours.
Arkivo executes a BAA with every covered-entity customer.
Byte-verified migration: nothing is retired at source until a checksum-verified copy exists in your storage.
Compliance program status, including target dates and what evidence exists: see the table below.
Where our compliance program actually stands
We publish status rather than badges. Nothing here is claimed as achieved until a report exists and we can hand it to you. Regulations are listed as alignment because no certification exists for them.
| Item | Status | Target date | Evidence |
|---|---|---|---|
SOC 2 Type IAttestation SOC 2 Type I — controls design attestation. Program underway; target Q1 2027. | In progress Program underway. Not yet attested. | None yet | |
SOC 2 Type IIAttestation SOC 2 Type II — observation window opens at production cutover (target Q2 2027); report targeted Q4 2027. | Planned Committed and scheduled. Not yet started. | None yet | |
SOC 1Attestation SOC 1 — not applicable to Arkivo's scope. Arkivo does not process transactions affecting customer financial reporting. Available on request if a control objective is identified. | Not applicable Out of scope for what Arkivo does. | — | None yet |
HIPAARegulation HIPAA — no certification exists. Arkivo executes a BAA and is architected so PHI never leaves the customer's own cloud tenant. | Alignment only A regulation we design to — no certification exists for it. | — | None yet |
GDPRRegulation GDPR — no certification exists. Recordings stay in the customer's own tenant and region, so residency, access, and erasure remain under the customer's own controller obligations and agreements. | Alignment only A regulation we design to — no certification exists for it. | — | None yet |
CCPA / CPRARegulation CCPA / CPRA — no certification exists. Consumer data stays in the customer's own tenant; access and deletion requests are served from storage the customer controls. | Alignment only A regulation we design to — no certification exists for it. | — | None yet |
FINRARegulation FINRA — no certification exists. Arkivo is designed for the retention, legal-hold, and tamper-evident audit obligations broker-dealers carry, on storage the customer owns. | Alignment only A regulation we design to — no certification exists for it. | — | None yet |
MiFID IIRegulation MiFID II — no certification exists. Arkivo is designed for trade-related call-recording retention obligations, on storage the customer owns. | Alignment only A regulation we design to — no certification exists for it. | — | None yet |
PCI DSSCertification PCI DSS — Arkivo holds no PCI validation. Arkivo does not store, process, or transmit cardholder data. PCI-scope redaction is a product feature, not a validation Arkivo holds. | Not applicable Out of scope for what Arkivo does. | — | None yet |
Third-party penetration testAttestation Third-party penetration test — planned; first engagement targeted by 31 December 2026. No report exists today. | Planned Committed and scheduled. Not yet started. | None yet | |
HIPAA Security Risk AssessmentAttestation HIPAA Security Risk Assessment — underway; target completion 31 October 2026. | In progress Program underway. Not yet attested. | None yet |
Last verified 16 July 2026. Arkivo executes a BAA with every covered-entity customer. Questions from a security review? Ask us directly.
The right people see the right recordings — and nothing more
Plug into your identity provider, map your org onto built-in personas, and scope every action down to a single team or a single user.
Eight built-in personas, ready on day one
Each role ships with a sensible default scope — from an agent who only ever sees their own calls, to org-wide compliance and audit access.
Custom roles & an editable permission matrix
Personas are only the starting point. Build your own roles and toggle each permission independently, with access scoped to an organization, division, team, or a single user.
Own your recordings. Keep the experience.
See the control plane live in minutes, or talk to us about migrating off NICE or Genesys into the cloud you already trust. No rip-and-replace, no lost calls.
No data migration required to evaluate · Your cloud, your keys, your data