Apifonica operates according to enterprise security and compliance standards, including ISO/IEC 27001:2022 certification and PCI DSS SAQ A attestation. Operated by SmartTel Plus OÜ (Estonia, EU) with our German group entity Tenios GmbH registered with BNetzA (German Federal Network Agency)
Voice and Messaging are protected by SRTP for voice media, TLS in transit and AES-256 at rest, supported by continuous 24/7 security monitoring.
The platform is designed to support regulatory requirements across finance, healthcare and public sector environments, including GDPR compliance and alignment with NIS2 and the EU AI Act (minimal/limited-risk classification).
The platform operates as an aligned ICT third-party service provider, supporting DORA obligations of financial-sector clients - including ICT risk management, incident reporting, resilience testing, exit provisions and third-party governance.
All enterprise data remains within EU-based infrastructure hosted in Frankfurt, Germany. Customer data is never used for AI model training.