Compliance
The rules your contact center has to follow, handled in the product
Recording consent, texting consent, payment handling, data erasure and audit evidence are built into every conversation — not bolted on at review time.
Call recording disclosure
Every inbound and outbound call opens with the spoken line “This call is monitored and recorded for quality and training purposes.” The disclosure cannot be skipped, and the recording is stored privately with signed, expiring links.
- Two-party consent friendly
- Dual-channel audio
- Signed, time-limited playback links
TCPA texting rules
Two-way texting honours STOP, UNSUBSCRIBE and START instantly. Opted-out numbers are blocked at the send layer, not just in the interface.
- Instant opt-out
- Opt-out ledger per workspace
- Quiet-hours aware outbound
PCI zero-scope payments
Katalyst never captures a card number. Payments happen through secure links, and card-shaped sequences are stripped from transcripts and logs before storage.
- No card data on phone lines
- No card data in recordings
- Automatic card masking
GDPR & CCPA erasure
A customer can be erased by phone number. Recording audio is destroyed, transcripts wiped, identifiers anonymised, and a tamper-evident record is written to your audit trail.
- Right to be forgotten
- Cryptographic audit record
- Runs in minutes, not weeks
HIPAA readiness
Turning on the HIPAA profile enforces short session timeouts, strict signed-URL expiry and mandatory transcript masking. Business Associate Agreements are available on request.
- Strict link expiry
- Mandatory PII masking
- BAA on request
SOC 2 aligned audit logging
Every sensitive action — listening to a recording, exporting payroll, exporting texts, changing security settings — is written to an append-only ledger you can search and export for auditors.
- Append-only ledger
- Actor, time, IP captured
- CSV export for auditors