Skip to content
White-LabelComplianceComparisonsVoice AI

Vapi vs Retell: HIPAA and SOC 2 Compliance Compared (2026)

Vapi vs Retell HIPAA and SOC 2 compliance compared for 2026: Vapi gates HIPAA behind a $2,000/mo add-on; Retell offers a self-serve BAA. Full breakdown.

Ming Xu
Ming XuCo-Founder & CIO
6 min read
Vapi vs Retell: HIPAA and SOC 2 Compliance Compared (2026)

Vapi vs Retell: HIPAA and SOC 2 Compliance Compared (2026)

Vapi and Retell both hold SOC 2 Type II and can be made HIPAA-eligible, but they get there very differently. Vapi charges $2,000/month for HIPAA as an add-on, plus a separate $1,000/month for zero data retention, on top of its $0.05/min platform fee (the language model, text-to-speech, and transcription are billed separately, so the realistic all-in cost is roughly $0.15/min). Retell is cheaper on paper at $0.07 to $0.31/min component-priced, and its standout is a self-serve Business Associate Agreement (BAA, the contract that makes a vendor HIPAA-eligible) on its pay-as-you-go plan, which is genuinely friendlier for a first healthcare client. Neither offers native white-label, so an agency reselling into regulated verticals has to add a wrapper and extend its BAA chain across every vendor in the stack. Trillet includes HIPAA, SOC 2 Type II, and ISO 27001 on its native white-label platform at no add-on, from $99/month. This article compares the two on HIPAA, SOC 2, the BAA chain, and what all of it means for regulated resale, as of August 2026.

Compliance is where a voice AI deal for a healthcare, legal, or financial client is won or lost. The platform that answers the phone is only compliant if every vendor touching call audio and transcripts is under contract, and developer infrastructure like Vapi and Retell pushes that assembly work onto you.

Does Vapi support HIPAA and SOC 2?

Vapi supports both, but HIPAA is a paid add-on rather than a default. As of August 2026, Vapi holds SOC 2 Type II and offers HIPAA compliance for $2,000/month, with zero data retention available as a separate $1,000/month option. That is up to $3,000/month in fixed compliance fees before a single patient call connects, sitting on top of the $0.05/min platform fee and the at-cost language model, speech-to-text, and text-to-speech you pay for on top.

The economics only work at volume. If you are an agency signing your first healthcare client at a few hundred dollars a month, a $2,000/month HIPAA line item erases the margin on that account and several more. Vapi's design assumes a technical team with enough regulated traffic to absorb the fixed cost, not an agency testing a new vertical.

What to do: if you are evaluating Vapi for regulated work, price the HIPAA and zero-data-retention add-ons into your per-client math from day one, not as a "later" cost. At low volume, the fixed monthly fee, not the per-minute rate, is the number that decides whether the account is profitable.

Does Retell support HIPAA and SOC 2?

Retell supports both, and its self-serve BAA is the more agency-friendly approach of the two. As of August 2026, Retell holds SOC 2 Type II and offers a self-serve BAA on its pay-as-you-go plan, so a healthcare client does not force you onto an annual enterprise contract or a five-figure minimum. Credit where it is due: not gating HIPAA behind a sales call and a fixed monthly fee is a real advantage over Vapi, and for a small agency it lowers the barrier to a first regulated deployment considerably.

Retell's pricing is component-priced at $0.07 to $0.31/min, reflecting the voice infrastructure, the language model, and telephony stacked together. The wide range matters for compliance because the top of it usually means a premium language model, and which model you pick has BAA implications (more on that below).

What to do: if you want the lowest-friction path to a signed BAA on a developer platform, Retell's self-serve option is the better of the two. Just confirm in writing that the BAA covers the specific models and telephony you actually route through, not only Retell's own infrastructure layer.

The compliance cost nobody quotes: the BAA and subprocessor chain

The real HIPAA exposure on Vapi and Retell is not the headline add-on fee, it is the subprocessor chain: HIPAA compliance is only as strong as the weakest signed BAA among every vendor that touches protected health information. Both platforms are component-priced and model-agnostic, which is a genuine strength for engineering flexibility and a genuine liability for compliance, because you are the one stitching the vendors together.

A working deployment on either platform typically involves the voice infrastructure vendor, a language model provider, a text-to-speech vendor, and a telephony provider. Every one of those handles call audio or transcripts, so every one needs a BAA on file for the deployment to be HIPAA-compliant. Bring-your-own-key setups make this sharper: if you supply your own language model key, the model provider is your subprocessor and your responsibility to cover, not the platform's. A single vendor in that chain without a signed BAA is a compliance gap regardless of what the platform itself certifies.

What to do: before you resell either platform into healthcare, map every vendor in your call path and get a BAA from each, then keep that map current every time you change a model or voice. If maintaining a multi-vendor BAA chain per client is not something you want to own, a single-vendor native platform removes the chain entirely.

Neither Vapi nor Retell offers native white-label for regulated resale

Neither platform ships a native white-label layer, which is the structural problem for an agency reselling compliant voice AI. Vapi and Retell are developer infrastructure: they expose APIs and SDKs, not branded client dashboards, sub-accounts, or per-client billing. To resell under your own brand you either build that layer with engineers or subscribe to a third-party wrapper such as Vapify or VoiceAIWrapper.

For regulated verticals, the wrapper route compounds the compliance problem. The wrapper now sits in the path of protected health information too, so it becomes another subprocessor that needs a BAA, and you are answering to your client for a stack you assembled from a wrapper, an infrastructure vendor, a model provider, and a telephony vendor. When something breaks or an auditor asks who is accountable for the data, you are the general contractor for a building you do not own. For the architectural trade-off in full, see voice AI wrapper vs native platform.

What to do: if regulated resale is the plan, count the wrapper as both a second bill and a second compliance surface, then compare that total against a native platform that includes white-label and holds the certifications itself.

How Trillet includes HIPAA, SOC 2, and ISO 27001 on a native white-label platform

Trillet is a native voice AI platform that includes HIPAA, SOC 2 Type II, ISO 27001, GDPR, TCPA, ACMA, and DNCR on every plan at no add-on, starting at $99/month (Studio) and $299/month (Agency, unlimited sub-accounts) with $0.12/min all-in usage. Because Trillet owns its stack end to end rather than assembling third-party components, there is one vendor and one BAA rather than a chain to maintain. Public ISO 27001 certification is not something either Vapi or Retell prominently advertises as of August 2026 (verify directly if it matters to a client), whereas Trillet holds and includes it.

For agencies, this is the defining difference. Trillet co-delivers regulated deployments as the agency's compliance and infrastructure partner: it carries the certifications so a smaller reseller can pursue healthcare, legal, and financial clients that a wrapper or a raw dev platform locks them out of. Enterprise deployments add APRA CPS 234 and IRAP alongside CREST-certified independent penetration testing and a financially guaranteed 99.99% uptime SLA, with configurable data residency and Australian onshore storage for clients that require it.

The trade-off is honest: Vapi and Retell give a technical team more granular control over models and components than Trillet's all-in model does. If your business is building a custom voice product and you have engineers to run a multi-vendor BAA chain, that control is worth something. If your business is reselling compliant voice agents under your own brand, the assembly work is overhead, not an asset. For the reseller playbook, see the white-label voice AI platform guide for agencies and the agency white-label pricing.

Vapi vs Retell vs Trillet: compliance and cost at a glance

Here is the compliance and cost picture side by side, as of August 2026. Per-minute figures are realistic all-in ranges, not headline platform fees.

FactorVapiRetellTrillet
HIPAA / BAA$2,000/month add-onSelf-serve BAA on PAYGIncluded
SOC 2 Type IIYesYesYes
ISO 27001Not prominently publishedNot prominently publishedIncluded
Zero data retention$1,000/month add-onConfigurableIncluded controls
Native white-labelNo (wrapper required)No (wrapper required)Included
BAA chainMulti-vendorMulti-vendorSingle vendor
All-in per-minute~$0.15 (higher at premium)~$0.07 to $0.31$0.12
Data residency (AU)Not offered nativelyNot offered nativelyOnshore available

The pattern is consistent. Vapi and Retell are strong, flexible infrastructure sold to engineers, and Retell's self-serve BAA is the friendlier compliance on-ramp of the two. But both leave the agency assembling and certifying a multi-vendor stack, and neither includes the white-label layer that regulated resale requires. Trillet trades component-level control for a single-vendor platform that bundles the certifications and the branding an agency actually resells.

Frequently Asked Questions

Is Vapi HIPAA compliant?

Vapi can be HIPAA-eligible, but only on a paid add-on. As of August 2026, HIPAA compliance is $2,000/month with a separate $1,000/month zero-data-retention option, on top of Vapi's $0.05/min platform fee and at-cost models. Vapi also holds SOC 2 Type II. For a low-volume agency, the fixed monthly HIPAA fee, not the per-minute rate, is usually the deciding cost.

Does Retell offer a BAA for HIPAA?

Yes. Retell offers a self-serve Business Associate Agreement on its pay-as-you-go plan as of August 2026, which is more agency-friendly than gating HIPAA behind an annual enterprise contract. Retell also holds SOC 2 Type II. Confirm the BAA covers the specific language model and telephony you route through, since those are separate vendors in Retell's component-priced stack.

Do Vapi or Retell hold SOC 2 and ISO 27001?

Both hold SOC 2 Type II as of August 2026. Neither prominently publishes an ISO 27001 certification, so verify directly with the vendor if a client requires it. Trillet includes SOC 2 Type II and ISO 27001 (plus HIPAA, GDPR, TCPA, ACMA, and DNCR) on every plan at no extra cost.

Why does compliance cost more when reselling Vapi or Retell?

Because you are certifying a multi-vendor chain, not one vendor. HIPAA compliance requires a signed BAA from every subprocessor that touches call data: the infrastructure vendor, the language model provider, text-to-speech, and telephony. Neither Vapi nor Retell offers native white-label, so an agency also adds a wrapper, which becomes another subprocessor to cover. A native platform like Trillet reduces that to a single BAA.

What is the most compliant option for a regulated agency deal?

For an agency reselling into healthcare, legal, or finance under its own brand, a native platform that includes the certifications and the white-label layer is the lowest-risk path. Trillet includes HIPAA, SOC 2 Type II, and ISO 27001 from $99/month with a single-vendor BAA, so there is no multi-vendor chain or wrapper to certify. Vapi and Retell remain strong choices for engineering teams building a custom product with the capacity to manage compliance component by component.

Related articles