A compliance floor that cannot be turned off
Pre-dial scrubbing, AI disclosure, quiet hours, and instant opt-out are enforced in code on every plan, at $0. They are not settings — no configuration, plan, or support ticket disables them.
What we enforce, what we retain, and what we have — and haven’t — been audited for. No badges appear on this page before the report behind them exists.
Compliance on Vocapable is product behavior, not paperwork — these hold on every plan, for every tenant.
Pre-dial scrubbing, AI disclosure, quiet hours, and instant opt-out are enforced in code on every plan, at $0. They are not settings — no configuration, plan, or support ticket disables them.
Every dial attempt records what was checked, what the result was, and why the call was allowed or refused — kept so you can answer for any call after the fact.
The pre-dial scrub waterfall blocks the call when a check cannot complete. Uncertainty never resolves in favor of dialing.
An opt-out takes effect at once and lands in a suppression ledger that is retained indefinitely — ahead of the FCC’s tightening revocation timelines.
Numbers on our own carrier account carry exactly one kind of traffic: verified test calls to phone numbers you have proven you control. Production calling rides your own carrier account. This is enforced at the dial gate, not by policy document.
Purchased, rented, scraped, or appended contact lists are refused on the platform in all cases. Campaigns run on your own opt-in contacts.
One thing scrubbing cannot do: make an unlawful call lawful. Scrubbing blocks calls that must not happen — it never substitutes for the consent you are required to hold.
Traffic is encrypted in transit. Call recordings, transcripts, and compliance evidence are processed on our customers’ behalf as a service provider; payment cards are handled by Stripe and never stored by us.
Legal acceptances are append-only: each records the document version, the SHA-256 of the exact text presented, the signer, and a server-stamped IP and timestamp. The website and the product serve the same source text, so accepted and published text cannot drift.
API access is authenticated on every request, test and live modes are separated at the key level, and compliance-relevant actions are logged.
Stated plainly, because badge theater helps no one:
SOC 2 Type I — planned for our second product phase. Not started; no report exists today.
SOC 2 Type II — planned for the phase after that, once the Type I observation period can begin.
We hold no certifications today and display no badges until the report behind one exists. If your security review needs specifics before then, write to support@capstralabs.com and we’ll answer directly.
The full set — currently drafts under counsel review, published so you can read exactly what acceptance will mean.