Compliance

The rules your contact center has to follow, handled in the product

Recording consent, texting consent, payment handling, data erasure and audit evidence are built into every conversation — not bolted on at review time.

Call recording disclosure

Every inbound and outbound call opens with the spoken line “This call is monitored and recorded for quality and training purposes.” The disclosure cannot be skipped, and the recording is stored privately with signed, expiring links.
  • Two-party consent friendly
  • Dual-channel audio
  • Signed, time-limited playback links

TCPA texting rules

Two-way texting honours STOP, UNSUBSCRIBE and START instantly. Opted-out numbers are blocked at the send layer, not just in the interface.
  • Instant opt-out
  • Opt-out ledger per workspace
  • Quiet-hours aware outbound

PCI zero-scope payments

Katalyst never captures a card number. Payments happen through secure links, and card-shaped sequences are stripped from transcripts and logs before storage.
  • No card data on phone lines
  • No card data in recordings
  • Automatic card masking

GDPR & CCPA erasure

A customer can be erased by phone number. Recording audio is destroyed, transcripts wiped, identifiers anonymised, and a tamper-evident record is written to your audit trail.
  • Right to be forgotten
  • Cryptographic audit record
  • Runs in minutes, not weeks

HIPAA readiness

Turning on the HIPAA profile enforces short session timeouts, strict signed-URL expiry and mandatory transcript masking. Business Associate Agreements are available on request.
  • Strict link expiry
  • Mandatory PII masking
  • BAA on request

SOC 2 aligned audit logging

Every sensitive action — listening to a recording, exporting payroll, exporting texts, changing security settings — is written to an append-only ledger you can search and export for auditors.
  • Append-only ledger
  • Actor, time, IP captured
  • CSV export for auditors