← Quill Calls

Security & privacy

What Quill Calls does to protect call, visitor and attribution data, and what that does and doesn't mean for HIPAA.

Built in, not bolted on

Every table is scoped to your account by row-level security, enforced by the database itself — not application code that could have a bug in it. Visitor and attribution data gets the same protection as call recordings the moment it's linked to a call, not a separate "less protected" tier.

Call recordings and transcripts are only ever served through short-lived, signed URLs — never a public file link.

Every playback or download of a recording or transcript is written to an audit log: who, when, how.

Staff access is role-scoped on a minimum-necessary basis: an analyst role can see attribution and reporting, but never raw call recordings or transcripts.

Marketing-integration data leaving to Google Ads or GA4 passes through a code-level allowlist — only click/campaign identifiers and conversion values can ever leave; call recordings, transcripts and any free-text field never do.

Retention is configurable per account, with an automatic purge job — old recordings and transcripts don't linger.

What this page is not

This describes technical safeguards, not a compliance certification. HIPAA compliance also requires signed Business Associate Agreements with every vendor in the chain, a documented risk assessment, a breach notification procedure, and workforce training — none of which a status page can attest to on a vendor's behalf.

If you need to send real patient information through this product, talk to us first about which vendor BAAs are in place for your account before you do.

Questions

Contact your Quill Calls administrator, or reach out through Quill Hound if this product is part of a bundle.