- No SOC 2, no ISO 27001
- qallin holds neither today: no audit in hand, no certificate to attach. If your review requires a certified provider, we do not pass it, and no conversation changes that this quarter.
- No HIPAA BAA
- We do not sign business associate agreements. If protected health information would touch this line, qallin is the wrong tool.
- No SSO and no SCIM
- There is no SAML, no OIDC and no directory sync today. Accounts are invited and removed by an administrator inside the product. Whether that changes is not decided, so we will not give you a date.
- No SLA, no support contract
- No uptime commitment, no credit schedule, no named support contact you can put in a contract. When there is one it will be written down and public.
- Encrypted in transit. That is all.
- Calls and messages are encrypted in transit. We will not dress that up into a security posture statement — ask the specific question and we will answer it or say we cannot.
- Access by role, removal immediate
- A team sees what it owns; an administrator sees the account. Removing someone ends their access right away, on every device. That is not the same as directory-managed access.
- Off unless you turn it on
- Nothing is recorded by default. Where a state requires everyone’s consent, both sides hear an announcement that cannot be disabled. Whether a call may be recorded at all is your counsel’s question.
- A2P 10DLC first, and no 911
- US carriers require the brand and campaign registered before a business can text; we file it, and texting does not work until it clears. qallin runs alongside the phone in your pocket — emergency calls go through the device’s own dialer.