Knowledge Hub · Voice

How does FirstNet Compliance Recording protect call recordings?

Compliant Call Recording & Analytics · Answered by FirstNet Technology Services

Short answer

Recordings are kept in tamper-proof storage with rotating 256-bit AES encryption at rest and in transit. Admin and reviewer access requires multi-factor authentication, permissions can be limited by user, group, recording type and metadata, and every access is logged.

In detail

The layers of protection:

  • Encryption: AES-256 with periodic key rotation, for stored recordings and recordings in transit.
  • Tamper-proof storage: recordings cannot be altered or deleted outside policy, backed by immutable retention controls.
  • Access control: MFA on admin and reviewer roles, plus granular role-based permissions.
  • Audit logs: a chain-of-custody record of who accessed which recording, when and what they did.
  • Controlled sharing: sharing outside the platform, for example with regulators or legal counsel, is controlled and logged.
  • Defensible deletion: recordings are disposed of at the end of retention in a logged, policy-driven way.

Access can be tied to your existing identity provider through single sign-on, validated during design. For card and health data, the Conversation Analytics tier adds automated redaction from audio and transcripts.

FirstNet provisions encryption, MFA, roles and retention policies during onboarding, and owns escalation of any underlying platform incident through to closure.

Source: FirstNet Compliant Call Recording & Analytics service page →

Didn’t answer your question?

Call