Skip to content

Trust Center

What we enforce, what we retain, and what we have — and haven’t — been audited for. No badges appear on this page before the report behind them exists.

Compliance posture

Compliance on Vocapable is product behavior, not paperwork — these hold on every plan, for every tenant.

A compliance floor that cannot be turned off

Pre-dial scrubbing, AI disclosure, quiet hours, and instant opt-out are enforced in code on every plan, at $0. They are not settings — no configuration, plan, or support ticket disables them.

An evidence file for every call

Every dial attempt records what was checked, what the result was, and why the call was allowed or refused — kept so you can answer for any call after the fact.

Fail-closed scrubbing

The pre-dial scrub waterfall blocks the call when a check cannot complete. Uncertainty never resolves in favor of dialing.

Revocation honored immediately and permanently

An opt-out takes effect at once and lands in a suppression ledger that is retained indefinitely — ahead of the FCC’s tightening revocation timelines.

Platform numbers are test-only

Numbers on our own carrier account carry exactly one kind of traffic: verified test calls to phone numbers you have proven you control. Production calling rides your own carrier account. This is enforced at the dial gate, not by policy document.

No purchased lists

Purchased, rented, scraped, or appended contact lists are refused on the platform in all cases. Campaigns run on your own opt-in contacts.

One thing scrubbing cannot do: make an unlawful call lawful. Scrubbing blocks calls that must not happen — it never substitutes for the consent you are required to hold.

Security posture

Data handling

Traffic is encrypted in transit. Call recordings, transcripts, and compliance evidence are processed on our customers’ behalf as a service provider; payment cards are handled by Stripe and never stored by us.

Acceptance records

Legal acceptances are append-only: each records the document version, the SHA-256 of the exact text presented, the signer, and a server-stamped IP and timestamp. The website and the product serve the same source text, so accepted and published text cannot drift.

Access

API access is authenticated on every request, test and live modes are separated at the key level, and compliance-relevant actions are logged.

Certification roadmap

Stated plainly, because badge theater helps no one:

  • Planned

    SOC 2 Type I — planned for our second product phase. Not started; no report exists today.

  • Planned

    SOC 2 Type II — planned for the phase after that, once the Type I observation period can begin.

We hold no certifications today and display no badges until the report behind one exists. If your security review needs specifics before then, write to support@capstralabs.com and we’ll answer directly.

Legal documents

The full set — currently drafts under counsel review, published so you can read exactly what acceptance will mean.