Is this your company?Buyers are checking Reddy here. Claim reddy.io free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Reddy is an AI-powered Agent Operating System that transforms enterprise CX (Customer Experience) teams. Reddy combines hyper-realistic simulation training, live call assistance, and AI‑driven post‑call quality assurance. It accelerates onboarding, boosts agent performance, and ensures compliance, all while enabling seamless collaboration across L&D, QA, and ops teams.
SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Reddy SOC 2 compliant?
Reddy is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Reddy HIPAA compliant?
According to Reddy's public trust center, Reddy is HIPAA compliant. On SOC2C this listing is Listed.
Is Reddy PCI DSS compliant?
According to Reddy's public trust center, Reddy is PCI DSS compliant. On SOC2C this listing is Listed.
Is Reddy GDPR compliant?
According to Reddy's public trust center, Reddy is GDPR compliant. On SOC2C this listing is Listed.
Is Reddy SOC 2 Type I or Type II?
Reddy is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Reddy's SOC 2 for a vendor risk assessment?
Yes. Reddy's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Reddy penetration tested?
Reddy hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Reddy secure?
Security isn't a single yes/no, but Reddy is SOC 2 Type II compliant and holds SOC 2 Type II, HIPAA, PCI DSS, GDPR. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Reddy have a bug bounty or vulnerability disclosure program?
Reddy hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@reddy.io or via a /security page (Reddy lists a security contact).
Who are Reddy's subprocessors?
Reddy lists 9 subprocessors on its trust center, including Google Cloud Platform, Microsoft Azure, Anthropic, Deepgram, ElevenLabs. Buyers use this for fourth-party risk review.
Where does Reddy host or store data?
Reddy hosts on AWS, GCP, Azure. Data residency details are on its trust center.
Where is Reddy's trust center or security page?
Reddy's trust center is at https://trust.reddy.io. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Where can I find information about Reddy's uptime and downtimes?
We recommend checking out our Status Page: https://status.reddy.io/. This will give you the ability to subscribe for updates, view uptimes, be informed of any outages, and view historical data.
Where is my data stored with Reddy?
Your data in Reddy is stored on secure servers within our cloud environment. By default, we host data in the United States in trusted data centers operated by Google Cloud Provider (GCP). All data remains within our controlled environment; we do not offload customer data to unknown third parties. If you have specific data residency requirements, Reddy can support regional hosting requests.
What data does Reddy collect, and is it used to train AI models?
Reddy only collects data that is necessary to provide our service—such as simulation interactions, performance metrics, and transcripts needed for training and assisting your agents on live calls. We do not use your company’s data to train our general AI models or share it with other customers. Your data is isolated to your organization’s use of Reddy and is never mingled or reused externally. In addition, we minimize sensitive personal information in our system. Reddy does not require storing highly sensitive data like credit card numbers or government IDs for our simulations or analytics. We focus on operational data (e.g. QA scores, conversation content) and do not retain regulated personal data whenever possible . This means your data remains under your control and is only used to serve your team’s training and performance needs.
Who can access my data at Reddy, and how is access controlled?
Access to customer data within Reddy is highly restricted and monitored. Only a small number of authorized Reddy personnel — those who need access to support your account or maintain the system — can reach customer data, and only with management approval and on an as-needed basis. We have robust internal controls: all employees must use company SSO credentials with MFA to access our systems, and permissions are limited by role (principle of least privilege) . Administrative access to production databases or servers is logged and audited, so every action is tracked. We also require strict confidentiality agreements with our staff and provide regular security training so that everyone understands how to handle customer data responsibly.
What security certifications and compliance standards does Reddy meet?
Reddy maintains rigorous security and privacy compliance. We are SOC 2 Type II attested and have achieved HIPAA and PCI DSS compliance to protect sensitive data. We also adhere to global data protection regulations like GDPR and CCPA, ensuring our practices meet international standards for privacy . These certifications and frameworks demonstrate Reddy’s commitment to keeping your data secure and compliant with industry requirements.
How does Reddy protect and secure customer data?
We take a multi-layered approach to security, implementing strong controls at every level of our platform. Key measures include: - Enterprise-Grade Infrastructure: Reddy is hosted on leading cloud infrastructure with robust network security. We utilize virtual private clouds, firewalls, and continuous monitoring to safeguard our perimeter and prevent unauthorized access . - Encryption Everywhere: All customer data is encrypted both in transit and at rest. We use TLS (HTTPS) to protect data in transit, and AES-256 encryption to secure data at rest in our databases. This means your information is unreadable to unauthorized parties at all times. - Strong Access Controls: We enforce strict access control and authentication for our systems. Internally, Reddy uses single sign-on (SSO) with multi-factor authentication (MFA) for all employees, and we apply role-based access control with least privilege principles. Only authorized personnel with a business need can access customer data, and all access is logged and audited for accountability. - Secure Development Practices: Security is built into our development lifecycle. Our engineering team performs code reviews, uses automated security scans, and undergoes secure coding training to prevent vulnerabilities . We fix issues promptly to keep the platform safe.
Does Reddy conduct third-party security audits and penetration tests?
Yes. We regularly test our platform’s security both internally and with independent auditors. Reddy undergoes third-party penetration tests to probe for any vulnerabilities in our infrastructure and applications . In addition to annual pen tests, we use continuous vulnerability scanning and monitoring to catch issues year-round. Our security team follows industry best practices to triage and prioritize any identified vulnerabilities for quick resolution . Furthermore, as part of our SOC 2 audits and other compliance efforts, our controls are examined by external assessors to ensure we meet security standards. This proactive approach—regular audits, testing, and fast remediation—helps ensure Reddy’s platform remains secure and trustworthy.
How can I report a security vulnerability or incident to Reddy?
We encourage responsible disclosure and take security reports seriously. If you believe you’ve found a vulnerability or security issue in our platform, please contact our security team immediately at [Security@reddy.io](mailto:Security@reddy.io) with the relevant details. Thank you for helping us keep Reddy secure.
Is Reddy HIPAA compliant and will you sign a BAA for healthcare clients?
Yes. Reddy is HIPAA compliant – as noted above, we have implemented the necessary safeguards (administrative, technical, and physical) to protect Protected Health Information (PHI) . For our healthcare customers, we are happy to sign a Business Associate Agreement (BAA) that formalizes our responsibilities when handling your PHI. We ensure that any ePHI processed through Reddy is encrypted and access to it is strictly limited, in line with HIPAA requirements. Our team is trained on HIPAA privacy and security rules so that they understand how to manage health data appropriately. If you’re in a regulated healthcare industry, you can trust that Reddy will work with you to meet compliance needs and will execute a BAA to give you contractual assurance of our HIPAA obligations. Please contact us to initiate a BAA as part of your onboarding if required.
Do you encrypt data at rest —and in transit?
Yes. All customer data is encrypted in transit via TLS 1.2+ and at rest using industry-standard AES-256 encryption keys managed by our cloud provider. Keys are rotated on a scheduled basis, and access to key-management systems is restricted to a small, audited group of engineers.
Do you support Single Sign-On (SSO)?
Absolutely. Reddy integrates with leading identity providers—including Okta, Azure AD, Google Workspace and any SAML 2.0-compliant IdP—so your administrators can enforce centralized MFA, SCIM user-lifecycle management, and granular role mapping.
How do you monitor for security breaches?
We run 24 × 7 × 365 monitoring that includes: - Centralized logging & SIEM: Real-time ingestion of application, network and infrastructure logs into CrowdStrike with automated anomaly detection rules. - Intrusion detection & threat intel: Managed IDS/IPS and threat-intel feeds flag suspicious traffic, correlated against baselines. - Automated alerting & on-call: PagerDuty alerts route immediately to our security on-call rotation; incidents are triaged under our NIST-based IR plan. - Continuous vulnerability scanning: Weekly authenticated scans plus container image scanning during CI/CD.