Compensable

Trust & security

Our posture, stated precisely.

Legal buyers get burned by vendors rounding up. Each line below says exactly what's true today, in words your counsel can hold us to.

Tamper-evident audit trail

in the product

Every call event is appended to a SHA-256 hash chain, serialized per call, with an on-demand verification check (GET /audit/verify) that names the exact broken link if a record were altered. Tamper-evident, not tamper-proof.

AI disclosure

in the product

The agent discloses that it is an AI assistant at the start of every call — spoken, on every path, with wording you configure under counsel review. There is no 'sound human' mode, and there never will be.

Human oversight

in the product

Live transcripts stream to your team in real time; a supervisor can take over any call with one tap. Qualification decisions are made by deterministic rules you configure. The model proposes; the code decides.

Organization isolation

in the product

Every record is scoped to your organization: data, numbers, API keys, webhooks. Access is role-based via your identity provider. Cross-organization access is denied by design and covered by tests.

Outbound governance (The Floor)

in the product

Consent verification, DNC/opt-out suppression, statute-cited per-state quiet hours, and frequency caps run on every outbound call and text, can't be switched off by anyone, and stop on missing data.

SOC 2-aligned controls

in the product

The controls a SOC 2 audit examines — role-based access, audit logging, tenant isolation, encryption in transit and at rest — are in the product today, built to Type II expectations. The independent attestation is in motion; we'll publish the auditor's report when it's signed, not before.

HIPAA

in the product

The default voice pipeline runs on HIPAA-eligible cloud infrastructure under a signed Business Associate Agreement, configured accordingly. There is no such thing as 'HIPAA certified' software, so we don't claim it.

Data handling

Your docket is not our training set.

Claimant conversations are privileged-adjacent by nature. The platform is built accordingly.

  • Enterprise model paths.

    On our enterprise voice deployments, call content and prompts are not used to train the underlying foundation models, per the providers' terms.

  • Recording is configurable.

    Call recording follows a policy you set per organization. Recording-consent rules vary by state, and the configuration reflects that instead of defaulting to 'record everything.'

  • Named infrastructure.

    Voice runs on Google Cloud (Vertex AI) with AssemblyAI speech recognition and Cartesia synthesis over LiveKit; telephony via Vonage, Telnyx, or Twilio, your choice of carrier. We'll walk your security team through the full subprocessor list on request.

  • Exportable, always.

    Calls, transcripts, attribution records, and audit chains are scoped to your organization and exportable. Verifiable records you can't take with you wouldn't be worth much.

The fine print, in large print

Standing disclaimers

These appear in our footer, our contracts, and here, because a governance product that buries its own limits isn't one.

Disclosures · standing
  1. Compensable's outbound campaigns are designed to identify the AI assistant at the start of each call, consistent with the FCC's 2024 TCPA ruling on AI-generated voices and applicable state disclosure laws; disclosure language is configured per campaign with counsel review.
  2. Compensable is not a law firm and does not provide legal advice. AI-assisted intake, outreach, and qualification are not a substitute for attorney judgment or supervision.
  3. Customer is responsible for obtaining and documenting any consent required under the TCPA and applicable state laws before placing outbound calls or texts, and for honoring opt-out and Do-Not-Call requests in its broader program. Compensable provides governance controls and evidentiary records but does not by itself guarantee legal compliance.
  4. HIPAA-eligible deployment requires appropriate infrastructure under a signed Business Associate Agreement, configured accordingly; no software product is 'HIPAA certified.'
  5. Statements about model data use apply to enterprise/paid deployment paths per the providers' then-current terms.
  6. Audit trails are tamper-evident (hash-chained and verifiable), which is not the same as tamper-proof or 'immutable.'
  7. Performance figures (such as latency percentiles) reflect internal benchmarks on specific configurations and dates, and are not guaranteed for all carriers, regions, or deployments.

Thirty minutes. Ask the hard questions.

We'll run a live call, work a sample docket, and show you the system refusing a call it shouldn't make.