Security and compliance

Enterprise-grade security

What Newo is certified against, what each certification covers, and how to get the documentation your security team will ask for.

ISO/IEC 27001:2022

ISO/IEC 27001:2022

The international standard for an information security management system. It covers how security is governed rather than any single control: how risks are assessed, who owns them, how access and suppliers are managed, and how the whole system is reviewed and improved. Certification is issued by an accredited body after an audit, and maintained through surveillance audits.

Certified

SOC 2 Type 1

An independent examination of our controls against the AICPA Trust Services Criteria for security, availability and confidentiality. A Type 1 report assesses whether those controls are suitably designed as at a specific date. Ours was performed by A-Lign and returned an unqualified opinion, meaning the auditor took no exception to the controls as described.

Audited by A-Lign
HIPAA

HIPAA

Where Newo handles protected health information, we act as a Business Associate and sign a Business Associate Agreement before any PHI is processed. PHI is handled on infrastructure operating to the HIPAA Security Rule, including encryption, access control and audit logging. This matters most to medical, dental and orthodontic practices.

Business Associate Agreement available
GDPR

GDPR

You remain the data controller and Newo acts as your processor, working only on your documented instructions. Our data processing addendum names the subprocessors we use, sets out where data is held and when it is deleted, and covers the safeguards that apply when data moves between countries.

Processor terms published
Auth0

Role-based access control

Access to the platform is managed by role, so each person on your team reaches the data their job needs and nothing beyond it. Authentication runs on Auth0 rather than a password system of our own.

Built in
AES-256 encryption

256-bit encryption

Conversation data is encrypted with 256-bit keys, the same strength used across regulated industries. It applies to the recordings, transcripts and structured data an agent produces, not only to the connection it travels over.

Built in

Documentation for your security review

The legal terms are public and linked below. The SOC 2 report and the detailed security documentation are shared under NDA: ask during a demo or through your account contact and we will send them across.

Bring your security questions

Book a call and we will go through the controls, the reports and anything your review needs.