Compliance frameworks, security audits, and quality certifications this company maintains.
Bandwidth maintains SOC 2 Type II certification for its cloud communications platform and carrier infrastructure, providing enterprise customers with independent assurance of security, availability, and confidentiality controls across its network operations.
Bandwidth's information security management system is ISO 27001 certified, covering its cloud voice, messaging, and 911 infrastructure operations to ensure systematic protection of communications data processed on behalf of enterprise and UCaaS customers.
Regulatory
FCC Licensed Carrier
CompliantBandwidth holds FCC licenses as an authorized US telecommunications carrier, including CLEC and IXC authority, enabling it to provide legally compliant voice origination, termination, and 911 services directly to enterprises without relying on third-party carrier partnerships.
Bandwidth fully implements STIR/SHAKEN caller authentication on its voice network, digitally signing all originating calls to combat spoofed caller ID and comply with FCC mandate requirements protecting consumers from illegal robocall operations.
Safety
Kari's Law and RAY BAUM'S Act
CompliantBandwidth's 911 platform is compliant with Kari's Law and RAY BAUM'S Act requirements, ensuring that enterprise UCaaS customers using Bandwidth's emergency calling services can route 911 calls with accurate dispatchable location information to the correct PSAP.
Bandwidth is a founding participant in the 10DLC campaign registration ecosystem and operates as a carrier in the Campaign Registry, enforcing compliant A2P SMS sending for all enterprise customers and rejecting unregistered traffic in accordance with CTIA messaging principles.
Bandwidth complies with GDPR for European operations, particularly through its Voxbone subsidiary operating in the EU, maintaining data processing agreements and EU-based data residency for communications data processed on behalf of European enterprise customers.
Bandwidth provides HIPAA-compliant voice and messaging services for healthcare enterprise customers, executing Business Associate Agreements and operating infrastructure controls that support healthcare organizations meeting HIPAA security rule requirements for communications data.
Bandwidth is PCI DSS certified to support payment-related voice and SMS use cases, including IVR payment processing and transaction authentication calling that handles cardholder data within Bandwidth's carrier-grade secure infrastructure.
As a licensed US carrier, Bandwidth complies with FCC Customer Proprietary Network Information (CPNI) regulations, restricting how it collects, uses, and discloses subscriber communications data and implementing mandatory CPNI annual certification and safeguard procedures.