No Security Certification, But a Public Record
Enterprise buyers ask for a certificate and we do not have one. Instead of pretending otherwise, we publish every measure with its date and its evidence.

Sooner or later every enterprise sales conversation reaches the same question: do you hold a security certification? Our answer is no, and this article is about what we say next.
We do not hold ISO 27001 and we do not have a SOC 2 report. Claiming security without certification is easy; showing it is the part that requires a different kind of work.
What a certificate actually does
Certificates are not meaningless, and it would be convenient but dishonest to argue otherwise. ISO 27001 shows an independent auditor confirmed a company manages information security systematically.
For an enterprise buyer the function is clear: nobody has time to examine every supplier individually. A certificate lets them delegate that examination to someone else.
If a bank or an insurer is buying, it is frequently mandatory rather than preferred, and no amount of transparency substitutes for it in those procurement processes.
But there is one thing a certificate does not tell you: what is happening today. Audits happen annually, the scope is written in the document, and that scope is usually narrower than the buyer assumes.
Why we do not have one yet
Two reasons, both boring and both true. Neither of them is that certification is unnecessary, which is a claim we would not make.
- Cost and time: certification with consultancy and audit runs for months and needs a serious budget, which at this stage comes straight out of the product
- Customer profile: our buyers today are franchise and dealership networks rather than banks, and this threshold has not yet appeared in their procurement
- Scope honesty: certifying a system that is still changing shape produces a document about a version that no longer exists
This is a statement about priority rather than about value. When the customer profile changes, the decision changes with it, and we would rather say that plainly than invent a policy reason.
What we do instead
What a certificate gives a buyer is an assurance. If we cannot offer an assurance, the only honest thing left is transparency about what we did and when.
The record we keep works on a simple rule. Every measure is written down with three things attached to it, and the third is the one that matters.
- 1.Date: when it was applied
- 2.What was done: one sentence, technically specific
- 3.Evidence: how it can be verified, a query result, a status code, a measurement
The third element is decisive. We use encryption is a claim; backups are encrypted with a key held separately is a statement somebody outside the company can check.
Why evidence beats assurance for a small vendor
A small vendor has no reputation to borrow from, so an unverifiable claim carries almost no weight. Evidence is the only currency available, and it happens to be the more useful one.
What the record looks like
Six lines from that record are below, taken verbatim rather than summarised. Each one names a date, a measure and something a reader can check without asking us.
| Date | Measure | Evidence |
|---|---|---|
| 28 July | Raw message bodies cleared from the database | Populated rows: 0 |
| 29 July | Consent check moved ahead of processing | A separate consent endpoint |
| 30 July | Webhook signature verification | Unsigned request returns 401 |
| 30 July | Tenant isolation | Access to another tenant's record returns 403 |
| 30 July | Continuous monitoring | 24 checks, every 5 minutes |
| 30 July | Daily encrypted backup | AES-256 |
This table has one weakness and one advantage compared with a certificate, and both are worth stating rather than leaving for a buyer to discover.
The weakness is that no independent auditor verified it. We wrote it ourselves, and a buyer is entitled to weigh it accordingly.
The advantage is that every line can be tested today. Send an unsigned request and see whether you get a 401. A certificate cannot offer that; it offers the result of an audit from a year ago.
A certificate says we were audited. A record says this is how it works right now, go ahead and try it.
The hardest part: publishing the gaps
This approach survives on one condition. If you publish only good news it collapses, and it collapses faster than a missing certificate ever would.
Operating without a certificate only works with the gaps published alongside the measures. A list without weaknesses reads as marketing, and buyers discount it accordingly.
A buyer who sees no gaps in a list of measures stops trusting the list and starts distrusting whoever wrote it. That reaction is correct, because no system has zero gaps.
- We do not hold ISO 27001 or SOC 2
- Our legal texts have not yet been reviewed by external counsel
- Data we delete continues to exist in encrypted backups for a further period, and we publish that period
The third is the one most often stated incorrectly by other vendors. Saying we delete after 30 days is easy and is simply not true when the backup copy is not counted.
What a recording can and cannot be kept for is a separate question with its own retention rules, and it deserves its own written policy rather than a sentence in a sales deck.
What to ask a supplier
If you are evaluating a software supplier, including us, these are the questions worth asking after the certificate question. Their answers tell you more than the certificate does.
- 1.Where does our data sit: which country, which provider?
- 2.Is our conversation data used in model training, and does the contract say so?
- 3.Who can access it, including the vendor's own staff, and under what conditions?
- 4.When we delete, how long does it remain in backups?
- 5.If there is a breach, how quickly are we told, and is that a commitment?
- 6.If we leave, in what format do we get our data back?
The last one is skipped most often. Data portability does not look like a security question, but supplier dependency is the most expensive long term risk in this category.
Working without a clear export answer is the one risk that grows quietly over time. Every month of data added raises the cost of leaving, which is precisely what makes it easy to postpone.
That question is also the hinge of the platform decision, which is covered in the article on building versus buying a voice agent.
For a running system, the equivalent of this record at the level of a single call is the audit trail, covered in the article on audit trails.
What the caller is told at the start belongs to the same discipline, and that is covered in the article on call transparency.
Where this ends up
When we hold a certificate we will publish that too. Until then we would rather not appear to hold a document we do not have, because that is the one claim a buyer can check instantly.
Security without certification is not a permanent position; it is an honest description of where a company is at a given moment, with the evidence attached so nobody has to take it on faith.
Want to see what is inside your own calls?
Callsense makes the intent, the objection and the next step in a conversation visible. A scoping call takes 30 minutes and needs no technical preparation.
Book a scoping call