{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"callrail","name":"CallRail","domain":"callrail.com","category":null,"one_liner":null,"trust_center_url":null,"security_page_url":null,"url":"https://certreports.com/vendors/callrail/security","last_verified_at":"2026-09-17T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"expired","state_label":"Expired","sentence":"Certificate expiry unknown date passed; no renewal found as of 17 Sep 2026.","kind":"listing","status_text":"Inactive","issued_at":"2020-07-15","expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/callrail/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/1627","fetched_at":"2026-09-17 15:47:07.638433+00","content_hash":"ffc6183b60777ba9c25d08d53a92c4886bc2dc7d4cb1ce6d04ef97ed96eec241","wayback_url":null,"quote":"CallRail: Inactive","confidence":1}]}],"brief":{"summary":"CallRail's listing in the EU-US Data Privacy Framework registry is marked Inactive as of 17 Sep 2026, with the original certification issued 15 Jul 2020 before it lapsed. No public evidence of a SOC 2 report was found for CallRail in this review. No public evidence of ISO/IEC 27001 certification was found for CallRail in this review. No public evidence of PCI DSS validation was found for CallRail in this review. No public evidence of GDPR compliance statements was found for CallRail in this review.","bullets":["EU-US Data Privacy Framework: listing Inactive, originally issued 15 Jul 2020 (as of 17 Sep 2026)","SOC 2 and ISO/IEC 27001: no public evidence found","PCI DSS and GDPR statements: no public evidence found"],"model":"claude-sonnet-5 (subscription)","generated_at":"2026-09-19 12:17:28.477846+00"},"legal_docs":[],"subprocessors":[],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-20T05:27:12.264Z"}