Trust & Compliance

We Secure, Encrypt & Protect Every Conversation

Rozper security is verified annually — SOC 2 Type II, GDPR, PCI-DSS. Encryption everywhere, SSO out of the box, and an audit trail streamed straight to your SIEM. The hard stuff, already done.

Independently audited every quarter

SOC 2 Type IISTIR/SHAKENGDPRPCI-DSS
rozper.com/security
Security posture · Live

Every layer, verified.

100%
Encryption coverage
TLS 1.3 · AES-256
12,480
Threats blocked (30d)
+9.2% vs prior
98/100
Audit score
SOC 2 Type II
Request security report
99.99%
Uptime SLA
150+
Countries
24/7
NOC
0
Breaches
How we protect you

Unlock trust with our security controls.

We treat security the way we treat the carrier network underneath Rozper — as critical infrastructure, monitored every second, audited by people who don't work for us.

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest, SRTP leg-by-leg — keys rotate automatically.

Encrypted100%
TLS 1.3SRTPAES-256

Carrier-grade infrastructure

Redundant points-of-presence, active-active failover, isolated tenant data.

US-EastActive
EU-WestActive
APACActive

Access controls

Least-privilege by default — SSO, SCIM, granular roles, and a fully audited action log.

Team access
AAdminFull access
AAgentScoped
AAuditorRead-only
AAPI keyScoped

Continuous assurance

Quarterly pen tests, weekly dependency scans, and a live bug bounty program.

Carrier & call protection

Every call authenticated at the carrier level, with dynamic emergency routing.

STIR/SHAKENAttested
E911 routingActive
Compliance & audits

Certified, in writing.

Request our latest reports through your account team. Audit packs include the controls matrix, executive summary, and the pen-test letter.

Request audit pack
SOC 2 Type II
Annual report, available under NDA.
ISO 27001
Information security management.
ISO 27017
Cloud-specific security controls.
ISO 27018
PII protection in cloud services.
HIPAA · BAA
Available for Enterprise customers.
GDPR · UK GDPR
DPA + SCCs on request.
PCI DSS · SAQ-A
For card-handling integrations.
CCPA / CPRA
California consumer rights.
Sub-processors

Who touches your data.

The short list. The full register, with regions and contract tiers, is in the customer console.

Provider
Purpose
Region
AWS
Compute & storage
US · EU · APAC
Cloudflare
Edge & WAF
Global
Twilio Networking
Number inventory
Global
Stripe
Billing & payments
US · EU
Data residency

Pick a region. Stay there.

Choose where your tenant lives at signup. Recordings, transcripts, and CDRs are pinned to that region — including backups.

  • US, EU, and APAC regions
    Active-active across three AZs each. Pinning is enforced at the storage layer, not just the routing layer.
  • On-prem session border control
    Optional. Customer-deployed SBC for regulated traffic patterns.
  • Tenant-level encryption keys
    BYOK with AWS KMS, GCP KMS, or HashiCorp Vault on Enterprise.
Trust & Compliance

Questions before you sign the DPA.

Yes. The current SOC 2 Type II report, ISO certificates, and pen-test letter are available under NDA — request them from your account team or via the audit pack link above.

Security shouldn't be a paid add-on.

Every plan ships with the same audited controls, encryption, and carrier-grade protection — no security tier to upgrade into.