How we protect your data and your customers'.
Security is a delivery requirement at National Networks, not a sales artifact. Our certifications, controls, and program documentation are reviewed by every client during onboarding.
Certifications & frameworks
- SOC 2 Type II — Annual audit covering security, availability, confidentiality, and processing integrity. Reports available under NDA.
- PCI DSS — Compliant environments for clients with cardholder data. Segregated tooling and least-privilege agent access.
- HIPAA-aligned — Business associate agreements available. Trained agents on minimum-necessary disclosure for health-vertical work.
- GDPR — Data Processing Agreement template available; EU-resident data handled under approved standard contractual clauses.
- ISO 27001 — Information security management system certified across all delivery locations.
Program highlights
All agents complete security and privacy training before they take a live customer interaction, and recertify annually. Workstations are company-owned and managed; we do not allow BYOD on any program. Recording, screen capture, and clipboard access are controlled centrally with audit logs.
We maintain a 24/7 security operations capability and run quarterly tabletop exercises across incident response, business continuity, and physical-security scenarios. Penetration testing is performed at least annually by an independent third party; remediation reports are shared with clients during evaluation.
Sub-processors and locations
We process customer data in the United States, Mexico, and Costa Rica. Sub-processor list and cross-border transfer mechanisms are documented in our DPA and updated with at least 30 days' notice of any material change.
Reporting a vulnerability
If you believe you've discovered a security issue affecting National Networks, please email legal@natlnetworks.com. We acknowledge reports within one business day and follow a coordinated disclosure process.