Security
How we protect your business
Virtual assistant security at AssistBPO starts with who does the work: employed, background-checked staff under an NDA per client, working from the group's offices on managed devices with no local storage, through your own user accounts with MFA and the least access the desk needs.
Access is monitored, recorded calls carry a notice, assistants never take card numbers, and healthcare desks use HIPAA-trained staff under a BAA. Certifications are listed only when held.
Who will be working on your account?
Background checks
Identity, employment history and criminal-record checks in the assistant's country of employment before any client data is touched, scoped to the role and to what your regulator expects.
NDA per client
Every assistant signs a confidentiality agreement on joining and a client-specific NDA for each desk they work. Your NDA template is accepted where you have one.
Employed, not freelance
Assistants are employees of SS Support Network LLC, paid, trained, managed and replaced by us. There is no marketplace, no subcontracting and no home-based freelancer on a client desk.
Security training
Security and confidentiality training at onboarding and every year, with a signed acknowledgement. Healthcare desks add HIPAA training before the first live day.
How do assistants get access to your systems?
Your accounts, your permissions
Assistants work inside your CRM, help desk, phone system, calendar and store through user accounts you create, with the permissions you choose. You can see, limit and revoke access at any time.
MFA on every account
Multi-factor authentication is required on every account our staff use, including yours, our portal and email. Shared logins are not permitted.
Least privilege
Each person sees only the clients and functions assigned to them: the named assistant, the backup and the team lead. Access is reviewed at the weekly review and removed on the last day of an assignment.
Monitored access
Logins are logged per person and per client. Where your software keeps an audit trail, every action is attributable to a named assistant. Logs are available to you on request.
Devices and workspace
Managed devices
Company-owned devices with disk encryption, endpoint protection, remote wipe and blocked USB storage. Personal devices are not used for client work.
No local storage
Your data stays in your systems. Downloads, local copies, screenshots and printing of client data are blocked by policy and by device configuration.
Secure workspace policy
Assistants work from the group's offices on a clean-desk, no-personal-phone-at-the-desk policy, with access-controlled floors and supervised shifts.
Calls, messages and payments
Call-recording notices
Where calls are recorded, callers hear a notice that follows the rules of their country and state. Recording is off wherever you ask, and recordings live in your phone platform under your retention setting.
No card data
Assistants never take, type or store card numbers, CVVs or bank credentials. Payments go through your portal, a payment link or a transfer to your own staff.
Consent and do-not-call
Outbound calls, texts and emails go out only with lawful consent and do-not-call scrubbing. The country rules are on the compliance page.
Data and incidents
Encrypted in transit and at rest
TLS everywhere, encryption at rest in the cloud tools you and we use. Client documents live in your systems or the client portal, not in inboxes or chat threads.
HIPAA-trained staff and a BAA
US healthcare clients receive a business associate agreement. Staff who touch protected health information are HIPAA-trained and limited to the minimum necessary for the desk.
Incident response
A written incident-response plan with named owners. You are notified without undue delay and within 72 hours of us becoming aware of an incident affecting your data, followed by a post-incident review.
Offboarding
On the last day our users are removed from your systems and the assistant's device profile is wiped. Working notes we hold are returned or deleted under the data processing agreement.
What data does AssistBPO keep, and for how long?
Most of your data never leaves your systems. This is the short list of what we hold ourselves.
| Records | Kept for | Why |
|---|---|---|
| Enquiry and staffing-plan records | 24 months after our last contact, unless you become a client | Reply, follow up with consent, keep a record of what was proposed |
| Client account records | Life of the contract, then the period tax and accounting law requires | Contracts, invoices and correspondence |
| Work done on your desk | Lives in your systems; our users are removed on the last day | Emails, tickets, bookings, CRM records and call recordings stay in your platforms under your retention rules |
| Job applications | 12 months after the role closes, unless the applicant asks otherwise | Recruiting for later openings |
| Access and security logs | As set in the data processing agreement | Attribution and incident investigation |
Which certifications does AssistBPO hold?
Certifications are listed only when held. This page carries no badges because we have not yet completed a third-party attestation. SOC 2 is on the roadmap with no date set; when a report is issued it will be listed here with the date and made available under NDA. Until then, the controls above are what we offer, and you are welcome to test them.
Country rules for calls, texts, email, HIPAA, GLBA and PCI are on the compliance page. Processor terms are summarized in the data processing agreement. How we hire and screen is on the how we hire page. Report a vulnerability to security@assistbpo.com or see security.txt.
Frequently asked questions
Is it safe to hire a virtual assistant from AssistBPO?
The controls above are what make it safe: employed staff who pass background checks, an NDA per client, access only through your own accounts with MFA, managed devices with no local storage, monitored logins and a written incident-response plan. You keep the systems, the data and the ability to revoke access at any moment. The remaining risk is the same as with any employee, and the team lead manages it with you.
Are you SOC 2 or ISO 27001 certified?
We list certifications only when held, and we do not use badges we have not earned. The controls on this page are in place today. SOC 2 is on the roadmap with no date set; when a report is issued it will appear here and be available under NDA. Until then, ask for the security policy summary and the access log for your desk.
Where do assistants work from and who employs them?
From the group's offices, on managed devices. SS Support Network LLC is registered in Vancouver, Washington, with a second office in Pakistan, and every assistant is an employee of the group. We do not use home-based freelancers or marketplace contractors for client desks.
How do you keep virtual assistant confidentiality with our customers' data?
Assistants see only what the desk needs, inside your systems, under your permissions. They sign an NDA for your account, work on devices that block downloads and printing, and are trained on confidentiality every year. Nothing is copied to personal devices, inboxes or chat apps, and access is logged per person.
Can assistants take payments over the phone?
No. Assistants never take or store card numbers, CVVs or bank credentials. They send a payment link, transfer the caller to your own staff, or guide the customer through your portal. That keeps card data out of our hands and out of scope for your payment provider.
What happens to call recordings?
Recordings are made in your phone platform, with a notice that follows the caller's country and state rules, and kept under your retention setting. We do not hold a separate copy. Where you prefer no recording, the desk runs without it and the QA scorecard uses live monitoring instead.
Do you sign a BAA for healthcare clients?
Yes. US healthcare clients receive a business associate agreement, staff who touch protected health information are HIPAA-trained, and access is limited to the minimum necessary for the desk. The group has run healthcare front desks under BAAs since 2020.
What happens when an assistant leaves or the engagement ends?
When an assistant leaves, their access is removed the same day and the backup who has shadowed your desk steps in while the team lead re-matches you. When the engagement ends, our users are removed from your systems, device profiles are wiped and any working notes we hold are returned or deleted under the data processing agreement.
Can we audit you?
Yes. Clients and their auditors can request the access log for their desk, the security policy summary, staff training records and the sub-processor list. On-site or remote audits are available on reasonable notice under the data processing agreement.
Ask an AI assistant to summarize this page
Opens the assistant with a prefilled prompt so you can check our claims against the page yourself.
Next step
Your desk, staffed. Wherever you are.
Tell us what is overloaded. A named person replies within 1 business day with a staffing plan, and we propose your assistant within 72 hours.
Or call +1-657-777-0006 during US, UK or Australian business hours, or hear our demo receptionist.
- A named assistant proposed within 72 hours
- Employed, screened and managed staff, never freelancers
- Your hours, your tools, your data