Your own suppression list, held per tenant, and the one list the platform reads on every call it places. Every opt-out the agent hears writes a durable suppression row before the call closes, and the same list is applied to the batch before a campaign runs and read live again in the instant before each dial — so an opt-out captured moments ago on another campaign suppresses the very next attempt rather than the next batch.
It is a floor control in the strict sense. No plan tier, feature flag, API field, support tool or compliance-mode setting switches it off, and if the live read is unavailable, dialing halts rather than proceeding without it. There is no configuration surface anywhere in the product that can name this control, which is why there is nothing to turn off — the absence is structural rather than a policy somebody is expected to keep.
Its rows are permanent. They survive erasure requests, churn and non-payment, because deleting one would cause exactly the recontact the person asked you to prevent. The data processing addendum states the carve-out in those terms: suppression, not amnesia.
The payoff is the one your risk register cares about. A person who asked you to stop is not called again by any campaign in your workspace, and you can produce the row that stopped it. How the arrangement you run on your own list is recorded beside it is covered under upstream list screening, and what the software performs on each dial is on the compliance engine page.