Security

How we protect your business

Virtual assistant security at AssistBPO starts with who does the work: employed, background-checked staff under an NDA per client, working from the group's offices on managed devices with no local storage, through your own user accounts with MFA and the least access the desk needs.

Access is monitored, recorded calls carry a notice, assistants never take card numbers, and healthcare desks use HIPAA-trained staff under a BAA. Certifications are listed only when held.

Who will be working on your account?

  • Background checks

    Identity, employment history and criminal-record checks in the assistant's country of employment before any client data is touched, scoped to the role and to what your regulator expects.

  • NDA per client

    Every assistant signs a confidentiality agreement on joining and a client-specific NDA for each desk they work. Your NDA template is accepted where you have one.

  • Employed, not freelance

    Assistants are employees of SS Support Network LLC, paid, trained, managed and replaced by us. There is no marketplace, no subcontracting and no home-based freelancer on a client desk.

  • Security training

    Security and confidentiality training at onboarding and every year, with a signed acknowledgement. Healthcare desks add HIPAA training before the first live day.

How do assistants get access to your systems?

  • Your accounts, your permissions

    Assistants work inside your CRM, help desk, phone system, calendar and store through user accounts you create, with the permissions you choose. You can see, limit and revoke access at any time.

  • MFA on every account

    Multi-factor authentication is required on every account our staff use, including yours, our portal and email. Shared logins are not permitted.

  • Least privilege

    Each person sees only the clients and functions assigned to them: the named assistant, the backup and the team lead. Access is reviewed at the weekly review and removed on the last day of an assignment.

  • Monitored access

    Logins are logged per person and per client. Where your software keeps an audit trail, every action is attributable to a named assistant. Logs are available to you on request.

Devices and workspace

  • Managed devices

    Company-owned devices with disk encryption, endpoint protection, remote wipe and blocked USB storage. Personal devices are not used for client work.

  • No local storage

    Your data stays in your systems. Downloads, local copies, screenshots and printing of client data are blocked by policy and by device configuration.

  • Secure workspace policy

    Assistants work from the group's offices on a clean-desk, no-personal-phone-at-the-desk policy, with access-controlled floors and supervised shifts.

Calls, messages and payments

  • Call-recording notices

    Where calls are recorded, callers hear a notice that follows the rules of their country and state. Recording is off wherever you ask, and recordings live in your phone platform under your retention setting.

  • No card data

    Assistants never take, type or store card numbers, CVVs or bank credentials. Payments go through your portal, a payment link or a transfer to your own staff.

  • Consent and do-not-call

    Outbound calls, texts and emails go out only with lawful consent and do-not-call scrubbing. The country rules are on the compliance page.

Data and incidents

  • Encrypted in transit and at rest

    TLS everywhere, encryption at rest in the cloud tools you and we use. Client documents live in your systems or the client portal, not in inboxes or chat threads.

  • HIPAA-trained staff and a BAA

    US healthcare clients receive a business associate agreement. Staff who touch protected health information are HIPAA-trained and limited to the minimum necessary for the desk.

  • Incident response

    A written incident-response plan with named owners. You are notified without undue delay and within 72 hours of us becoming aware of an incident affecting your data, followed by a post-incident review.

  • Offboarding

    On the last day our users are removed from your systems and the assistant's device profile is wiped. Working notes we hold are returned or deleted under the data processing agreement.

What data does AssistBPO keep, and for how long?

Most of your data never leaves your systems. This is the short list of what we hold ourselves.

RecordsKept forWhy
Enquiry and staffing-plan records24 months after our last contact, unless you become a clientReply, follow up with consent, keep a record of what was proposed
Client account recordsLife of the contract, then the period tax and accounting law requiresContracts, invoices and correspondence
Work done on your deskLives in your systems; our users are removed on the last dayEmails, tickets, bookings, CRM records and call recordings stay in your platforms under your retention rules
Job applications12 months after the role closes, unless the applicant asks otherwiseRecruiting for later openings
Access and security logsAs set in the data processing agreementAttribution and incident investigation

Which certifications does AssistBPO hold?

Certifications are listed only when held. This page carries no badges because we have not yet completed a third-party attestation. SOC 2 is on the roadmap with no date set; when a report is issued it will be listed here with the date and made available under NDA. Until then, the controls above are what we offer, and you are welcome to test them.

Frequently asked questions

Is it safe to hire a virtual assistant from AssistBPO?

The controls above are what make it safe: employed staff who pass background checks, an NDA per client, access only through your own accounts with MFA, managed devices with no local storage, monitored logins and a written incident-response plan. You keep the systems, the data and the ability to revoke access at any moment. The remaining risk is the same as with any employee, and the team lead manages it with you.

Are you SOC 2 or ISO 27001 certified?

We list certifications only when held, and we do not use badges we have not earned. The controls on this page are in place today. SOC 2 is on the roadmap with no date set; when a report is issued it will appear here and be available under NDA. Until then, ask for the security policy summary and the access log for your desk.

Where do assistants work from and who employs them?

From the group's offices, on managed devices. SS Support Network LLC is registered in Vancouver, Washington, with a second office in Pakistan, and every assistant is an employee of the group. We do not use home-based freelancers or marketplace contractors for client desks.

How do you keep virtual assistant confidentiality with our customers' data?

Assistants see only what the desk needs, inside your systems, under your permissions. They sign an NDA for your account, work on devices that block downloads and printing, and are trained on confidentiality every year. Nothing is copied to personal devices, inboxes or chat apps, and access is logged per person.

Can assistants take payments over the phone?

No. Assistants never take or store card numbers, CVVs or bank credentials. They send a payment link, transfer the caller to your own staff, or guide the customer through your portal. That keeps card data out of our hands and out of scope for your payment provider.

What happens to call recordings?

Recordings are made in your phone platform, with a notice that follows the caller's country and state rules, and kept under your retention setting. We do not hold a separate copy. Where you prefer no recording, the desk runs without it and the QA scorecard uses live monitoring instead.

Do you sign a BAA for healthcare clients?

Yes. US healthcare clients receive a business associate agreement, staff who touch protected health information are HIPAA-trained, and access is limited to the minimum necessary for the desk. The group has run healthcare front desks under BAAs since 2020.

What happens when an assistant leaves or the engagement ends?

When an assistant leaves, their access is removed the same day and the backup who has shadowed your desk steps in while the team lead re-matches you. When the engagement ends, our users are removed from your systems, device profiles are wiped and any working notes we hold are returned or deleted under the data processing agreement.

Can we audit you?

Yes. Clients and their auditors can request the access log for their desk, the security policy summary, staff training records and the sub-processor list. On-site or remote audits are available on reasonable notice under the data processing agreement.

Ask an AI assistant to summarize this page

Opens the assistant with a prefilled prompt so you can check our claims against the page yourself.

Next step

Your desk, staffed. Wherever you are.

Tell us what is overloaded. A named person replies within 1 business day with a staffing plan, and we propose your assistant within 72 hours.

Get a staffing plan Book a 20-minute call

Or call +1-657-777-0006 during US, UK or Australian business hours, or hear our demo receptionist.

  • A named assistant proposed within 72 hours
  • Employed, screened and managed staff, never freelancers
  • Your hours, your tools, your data
Call WhatsApp Staffing plan