SOC 2 · Microsoft SSPA · Amazon AVSP · Reg F

Zero compliance incidents
across 168,000 collections.

Built to pass your security review on the first try. Enterprise procurement teams approve us in under a week.

Request security docs View certifications
0
compliance incidents

Across 168,000+ collection sequences. Audited by Microsoft, Amazon, and independent SOC 2 assessors.

0 CFPB complaints 0 data breaches 0 FDCPA violations 168,000+ sequences run
Compliance & certifications
SOC 2 Compliant SSPA — Microsoft approved Regulation F / FDCPA 0 CFPB complaints

Built to pass your security review.

Every certification we hold was earned to meet the requirements of enterprise procurement teams, not checked for marketing. Certifications and third-party audits are held by Respaid Inc., the company operating AgentCollect.

SOC 2 Type II

Third-party audited. Security, availability, and confidentiality controls — independently verified, not self-reported.

Audit report available on request

Microsoft SSPA

Passed Microsoft's supplier security audit. If Microsoft's procurement approved us, yours can too.

Documentation available

Amazon AVSP

Full penetration test + Deep Dive Questionnaire passed. Required for vendors processing Amazon data.

Pentest completed

Regulation F / FDCPA

Timing windows, opt-outs, and dispute routing enforced at the system level on every engagement, including B2B collections where the FDCPA does not strictly require it. Zero CFPB complaints ever.

Zero CFPB complaints

Where your data lives. How it's protected.

No surprises. Every policy is in writing and available before you sign.

In-region storage

US engagements: AWS us-east-1, no cross-border transfers. International engagements: data-residency requirements scoped and applied per deployment.

AWS us-east-1 · in-region hosting

AES-256 at rest, TLS 1.3 in transit

Encryption keys managed and rotated via AWS KMS.

AES-256 · TLS 1.3 · AWS KMS

No data sold or shared

Never sold. Never shared. Never used to train AI models. Your data runs your campaign — nothing else.

Zero data monetization

Role-based access + MFA

Every internal access role-gated, logged, and reviewed quarterly. MFA required for all staff.

RBAC · MFA · Quarterly access review

Every escalation reviewed by a licensed attorney.

When AI can't resolve a balance, a licensed attorney steps in. No lawsuits — amicable resolution only.

Licensed attorney supervision

Every escalated case reviewed by a licensed attorney. All communications legally compliant.

Zero litigation risk

Amicable resolution only. No lawsuits, no garnishment, no court filings.

FDCPA-compliant at every step

Timing, language, and dispute validation enforced automatically at the system level.

Licensed attorney network

Licensed & verified

Scope Demand letters only
Litigation None — amicable only
FDCPA validation Automatic
Dispute handling Automatic

All 50 states covered.

Collection law varies by state. We maintain up-to-date compliance documentation for every US jurisdiction, available in our compliance hub. For international engagements, we scope and apply the local collection, privacy, and data-residency requirements during onboarding, including RBI-regulated deployments in India (with DPDP Act 2023 readiness) and GDPR-governed processing in Europe.

Browse the 50-state compliance hub

Pass your security review.
Ship in a week.

Security overview documentation available on request, no NDA needed. Full SOC 2 Type II report available under NDA. Most enterprise procurement teams approve us in 3-5 business days.

Book a security review View certifications

Security overview available without an NDA. Full SOC 2 Type II report under NDA.