Compliance
Voxtelesys Services Compliance
Our Compliance Capabilities
The Voxtelesys solution for 3CX Hosting is only established in facilities that hold and maintain a ‘Passed’ rating in compliance assessments with the following certificates:
These assessment results are not publicly attainable records. If documentation of Voxtelesys’ DC’s HIPAA Compliance assessment is required, such files can be arranged contingent of an NDA. Please note, the Voxtelesys solution for 3CX Hosting has not gone through ITAR/HIPAA/SOC2/SOC2 assessments.
CISA
Voxtelesys participates in the Cybersecurity and Infrastructure Security Agency’s Cyber Hygiene Service (CISA). The CISA is maintained by the Department of Homeland Security (DHS) to track new critical and/or high vulnerabilities, and potentially risky services.
CISA has conducted Cyber Hygiene, Remote Penetration Testing, and Tailored Risk & Vulnerability Assessments of Voxtelesys’ Critical Systems to identify compliance gaps, as well as provided recommendations for remediation. A few Cyber Hygiene tests include:
What can be done to improve security?
Changes to our default 3CX deployment can be made to increase system image security through encryption, process & policy. The following are some examples.
HIPAA - Health Insurance Portability and Accountability Act
Is 3CX HIPAA Compliant?
HIPAA compliance does not apply to software vendors directly but to the organizations that may store, process, and transmit electronically through it PHI/health data of users. Although 3CX is not audited for HIPAA compliance specifically, both 3CX Communication System and the 3CX Video Conferencing software are secure by design. Is VoxFax (Fax2Email) HIPAA Compliant?
Yes, all resting data is stored via AES256 encryption. All transitional data is sent via TLS encryption. Furthermore, we offer the ability to password protect PDFs for both sending / receiving faxes.
ITAR - U.S. International Traffic in Arms Regulations
While Voxtelesys is not registered with the Defense Trade Controls Compliance (DDTC), we still have taken the following measures to deter offshore security vulnerabilities:
GDPR - European Union’s (EU’s) General Data Protection Regulation
Currently, GDPR applies to citizens/members of corporations that directly have a presence within the EU.
Customers should seek their own legal Counsel regarding their own compliance status, jurisdiction requirements, and further actions that may need to occur.
Is 3CX GDPR Compliant?
GDPR, as such, does not apply to products directly. Its regulation is based on how customer and employee data is protected and what procedures are in place on the company’s policy level, as well as good practices.
In regard to data protection, the 3CX Communication System has multiple security features built-in that ensure protection. The following are some examples:
Furthermore, the configuration can be tweaked to strengthen accesses or clear periodically old data:
STIR/SHAKEN
Voxtelesys signs all calls originating on its service using STIR/SHAKEN, and is in compliance with the FCC Rules for STIR/SHAKEN (See Voxtelesys Robocall Mitigation Database Entry).
Voxtelesys is compliant with FCC requirements for protecting Consumer Proprietary Network Information.
3CX: Secure Communication at Every Step
3CX takes your communication security seriously, employing a robust multi-layered encryption strategy to protect your data throughout its journey. Whether you're accessing the system remotely, making calls from the mobile app, or sending emails, rest assured that your information is shielded from unauthorized access.
Multi-level Encryption Across Different Channels
Beyond web and mobile security, 3CX protects other communication channels too: