We’re working to raise the bar on mobile carrier transparency. This year, Cape completed two major external audits that are unique in telecom:
- Cape is now SOC 2 Type 2 compliant, across all five Trust Service Criteria: Security, Availability, Confidentiality, Processing Integrity, and Privacy. Most SOC 2-compliant companies only cover Security. Only 5% attempt Privacy, since it's the hardest to get. The major carriers' existing SOC 2 claims are scoped to narrow business tools like billing platforms. Ours covers the services that power your everyday service, consumer and enterprise alike.
- Cybersecurity firm Trail of Bits audited our Disappearing Call Logs feature. During the audit, they found no violation of the following two claims: (1) CDR files are being deleted within the retention policy, and (2) Cape does not extract or retain data from CDRs about individual consumer customers, except daily totals.
Why this matters right now
In July, the New York Times disclosed that phone and text records of several of its journalists, as well as their relatives, had been subpoenaed as part of a leak investigation, with records requested dating back months before the reporting in question.
Your call logs expose everyone in your orbit, not just you. A carrier that doesn't retain that metadata for months or years simply doesn't have it to hand over. Our Disappearing Call Logs feature, which deletes internal call records within 1 day instead of the years that they’re retained by other carriers.
Telcos hide behind the fine print
It's not just about government requests. A recent TechRepublic report on T-Mobile's expanding T-Life app shows how murky carrier privacy practices are by design: richer profiles and "interest-based preferences" are rolling out with no word on whether they'll feed advertising, layered on top of several overlapping ad programs and opt-outs scattered across app, account, and device settings.
Cape's answer: make it legible.
Check out our:
- Plain-language privacy policy summary that lays out, data type by data type, exactly what's collected and how long it's kept.
- Public Trust Center, where anyone can find our SOC 2 report, the Trail of Bits Disappearing Call Logs audit, app penetration tests, and more.
More News From Cape
- Cape x DeleteMe: We teamed up with DeleteMe to give Cape subscribers 40% off their first year of DeleteMe so they can clean up personal info that's already sitting with data brokers.
- Cape joins EFF, Access Now, and others at the FCC: Cape was the sole telecom signatory to a letter with the EFF, Access Now, and other privacy and civil-liberties groups urging the FCC to reject mandatory ID collection for phone service.
- CEO John Doyle in Broadband Breakfast: Our CEO argued the FCC's proposed "know-your-customer" rule — requiring carriers to store customers' government IDs for four years — would build exactly the centralized, identity-linked database foreign hackers already inside U.S. telecom networks are looking for.
- John Doyle in DefenseScoop: Doyle also wrote about decades-old signaling-network vulnerabilities now being used against U.S. troops overseas, and what industry, Congress, and the Pentagon can do about it.
Want more stories like these? Subscribe to Cape’s newsletter here.
Share it

