SECURITY & CONFIDENTIALITY

Your calls can contain sensitive information. We treat them that way.

Law-firm intake can involve prospective clients, existing clients, legal matters, personal information, and information your firm considers confidential or privileged. Security is not a footnote to the product.

Serious infrastructure. Clear boundaries. No vague security theater.

HighLevel has achieved SOC 2 Type II accreditation.

The HighLevel platform underlying FirmVoice also publishes an ISO/IEC 27001:2022 certificate and additional security materials through its Trust Center.

Those credentials belong to HighLevel. Redline Marketing and FirmVoice do not independently claim those certifications.

We would rather tell you exactly how the system works than hide behind a compliance logo.

FirmVoice is built on HighLevel and connects with the phone system, calendars, CRM, practice-management software, and other tools your firm chooses to use. Each part of that stack has its own security and data-handling responsibilities. We will be clear about what is ours, what belongs to a provider, and what your firm controls.

The security questions a law firm should actually ask.

Good vendor review is not just about badges. It is about what happens to caller information from the moment the phone rings until the data is exported or deleted.

01

Your caller data belongs to your firm

Client-specific caller and contact information remains your firm's data. We use it to provide and operate the service, not as a separate marketing asset.

02

Your calls are not training somebody else's AI

We do not use confidential call content or client-specific caller data to train third-party AI models in a way that makes your information available to other customers or the public.

03

We are transparent about retention

FirmVoice is not a zero-data-retention product. Recordings, transcripts, summaries, and contact records may be retained by the systems used to provide the service.

04

Access should be limited

Access depends on the accounts, permissions, and systems configured for your implementation. We map who needs access during setup.

05

Recording rules still matter

If calls are recorded or transcribed, your firm remains responsible for applicable notice, consent, ethical, and professional requirements.

06

Security does not stop at FirmVoice

Your phone provider, CRM, practice-management system, calendar, and other integrations may also receive or store caller information.

Good intake does not require collecting everything.

The agent should ask for information that serves the approved workflow. Sensitive information that is unnecessary for receptionist or intake purposes should not be collected simply because the technology can collect it.

  • Define approved intake fields
  • Limit access by role where supported
  • Review recording and consent requirements
  • Understand where data is stored
  • Use escalation for legal judgment

Your data should not become a hostage situation.

After cancellation, FirmVoice makes commercially reasonable efforts to provide reasonably exportable client-specific caller and contact data for up to 30 days. After that transition period, access may be disabled and data may be deleted, archived, or anonymized according to ordinary practices, legal requirements, and the capabilities of the underlying providers.

What law firms usually ask us.

Is FirmVoice SOC 2 certified?

Redline Marketing and FirmVoice do not represent that they independently hold a SOC 2 certification. The HighLevel platform underlying FirmVoice has achieved SOC 2 Type II accreditation and publishes additional security and compliance materials through its Trust Center.

Does the platform have ISO 27001?

HighLevel publishes an ISO/IEC 27001:2022 certificate through its Trust Center. That certification applies to HighLevel, not to Redline Marketing or FirmVoice independently.

Will our caller data be used to train someone else's AI?

FirmVoice does not use your confidential call content, recordings, transcripts, intake data, or client-specific caller data to train or improve a third-party AI model in a way that makes that information available to other customers or the public. Data may still be processed by third-party AI providers when necessary to provide the service.

Are calls recorded or transcribed?

They can be. FirmVoice may use recordings, transcripts, and summaries as part of the platform experience. Your firm remains responsible for determining what notice or consent is required under applicable law and professional obligations.

How long is data retained?

FirmVoice is not marketed as a zero-data-retention service. Retention depends in part on the underlying systems used. After termination, we make commercially reasonable efforts to provide reasonably exportable client-specific data for up to 30 days before access may be disabled and data may be deleted, archived, or anonymized under ordinary practices and provider capabilities.

Who owns caller data?

Your firm owns its client-specific caller and contact information. We use that information only as needed to provide, operate, maintain, secure, troubleshoot, and improve the service, subject to the applicable agreement and provider requirements.

Can we review security details before signing?

Yes. If your firm has a vendor-security questionnaire, procurement requirement, or specific confidentiality concern, bring it to us before implementation so we can confirm what the current FirmVoice stack supports.

Have a vendor-security questionnaire? Bring it.

We will work through your requirements and tell you what the current FirmVoice implementation can—and cannot—support before you go live.

Discuss Security Requirements