ElevenLabs Agents
ElevenLabs' voice and chat AI agent platform, operating across phone, web, WhatsApp, SMS and email. The vendor states the platform is LLM-agnostic - customers may bring their own model, call a frontier model via API, or use vendor-hosted models - reports 10M+ conversations per week, and lists integrations with Zapier, Salesforce, Stripe, HubSpot, Shopify, Zendesk, Genesys, Twilio and Amazon Connect. The page lists SOC 2 Type II, ISO 27001, ISO 42001, AIUC-1, HIPAA and PCI DSS Level 1 attestations without publishing certificates, auditor names or report dates, and offers regional data residency (US, EU, India), a zero-retention mode and on-prem options. On assurance, the vendor states it defines guardrails, runs simulations and validates agent behaviour with automated tests before deployment, and the page demonstrates a guardrail blocking a request at run time; for record-keeping it offers transcripts, conversation history and debug logs, with no claim that the record is complete, tamper-evident or immutable. The vendor separately states it is the first agent platform eligible for AI insurance through AIUC, once certified - conditional eligibility only, with no carrier, policy, limits, effective date or customer indemnity published. No outcome-linked payment term is published. Two claims carried in an earlier capture of this page - that all agent actions are logged and auditable, and that deterministic workflow gates and approval steps are available - are no longer on it; the word "approval" does not appear at all.
23 fields evidenced · 36 with no public information. Every value below links to the document it came from and the date we checked it.
2 of those are flagged for review: our own check found language in the cited source that may address the field. An editor has not adjudicated them yet.
1 of the evidenced values quotes wording our own later capture of the same page no longer contains. Marked below, awaiting an editor.
Also appears in
Trust gap
How this is scoredAre scope, spend, and authority enforced while the agent runs?
Re-cited 2026-08-25, score unchanged at 2. The original quote ("Define deterministic workflow gates and approval steps.") is absent from the 2026-08-18 capture, and "approval" now occurs zero times on the page - the human-approval half of the claim is withdrawn separately. The guardrail half survives and is what the 2 rested on: the page states "Define guardrails, run simulations, and validate agent behavior with automated tests" and demonstrates a guardrail returning "Request blocked by guardrail" on a financial-advice request. Enforcement is asserted at run time but its scope is not published, so it stays 2.
Judged Aug 5, 2026; evidence newer. We have since re-read Runtime governance, most recently on Aug 18, 2026. No one has re-scored this dimension against it — the score above stands, but it is older than the evidence below it. How current a score is
Is there a tamper-evident record of what it actually did?
Lowered 2026-08-25 from 2. The 2 rested on "All agent actions are logged and auditable so you can validate compliance before and after deployment.", which is absent from the 2026-08-18 capture of the same URL. What the current page supports is conversation-level review - transcripts, conversation history and debug logs - which is a record the customer can inspect, but not a record of all agent actions and with no claim of tamper-evidence. That is a 1, not a 2.
Judged Aug 5, 2026; evidence newer. We have since re-read Audit trail, most recently on Aug 18, 2026. No one has re-scored this dimension against it — the score above stands, but it is older than the evidence below it. How current a score is
How this gap gets closed →Are compliance obligations attached per engagement?
Page lists SOC 2 Type II, ISO 27001, ISO 42001, AIUC-1, HIPAA compliant and PCI DSS Level 1. Certification is asserted but no certificate, auditor name, report date or per-engagement compliance schedule is published, so not a 3.
This score counts Regulatory alignment as undisclosed, and that absence is flagged for review — the cited source may address it. If so, this score is too low. How we check absences
Judged Aug 5, 2026; evidence newer. We have since re-read Compliance certifications, most recently on Aug 18, 2026. No one has re-scored this dimension against it — the score above stands, but it is older than the evidence below it. How current a score is
Does payment depend on a verified result?
No public evidence found of payment linked to a verified outcome. The only pricing terms published on the page are usage-based ("15 minutes included for free") and a commercial licence inclusion. Absence is the finding.
How this gap gets closed →Can the deployment be insured, and is the customer indemnified?
Corrected 2026-08-25 from 0. The prior 0 ("no public evidence found") was honestly recorded against the 2026-08-05 capture, which contains zero occurrences of "insurance". The 2026-08-18 capture of the same URL states: "ElevenAgents is also the first agent platform eligible for AI insurance through AIUC, once certified." That is conditional eligibility through a named certification programme, not cover in force - no carrier, no published limits, no effective date and no customer indemnity - so it clears 0 (which asserts nothing at all is published) but goes no higher than 1. This remains a trust gap and the referral link is unchanged.
Judged Aug 5, 2026; evidence newer. We have since re-read Insurance available, most recently on Aug 18, 2026. No one has re-scored this dimension against it — the score above stands, but it is older than the evidence below it. How current a score is
How this gap gets closed →Assurance
- Insurance available
- Conditional eligibility only, not cover in force: the vendor states it is the first agent platform eligible for AI insurance through the AIUC programme, contingent on becoming certified. No carrier, policy, limits, effective date or customer indemnity is published on the page checked.
“ElevenAgents is also the first agent platform eligible for AI insurance through AIUC, once certified.”
elevenlabs.io · checked Aug 18, 2026 - Own liability cover
- no public informationelevenlabs.io · checked Aug 12, 2026 · source did not state this
- Insurance carriers
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Coverage limits
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Indemnification
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Liability cap
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Audit trail
- Conversation-level review only: the vendor offers transcripts, conversation history and debug logs alongside analytics. The page checked no longer claims that all agent actions are logged and auditable, and makes no claim of tamper-evidence or immutability.
“Track success rates, CSAT, language usage and more with built-in analytics - or dig deeper with full transcripts, conversation history, and debug logs.”
elevenlabs.io · checked Aug 18, 2026 - Tamper-evident log
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Explainability
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Runtime governance
- Pre-deployment guardrails and simulation testing, demonstrated on the page by a guardrail refusing a financial-advice request at run time. The earlier "deterministic workflow gates and approval steps" wording is no longer on the page.
“Define guardrails, run simulations, and validate agent behavior with automated tests”
elevenlabs.io · checked Aug 18, 2026 - Permission scopes
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Compliance certifications
- The enterprise strip on the vendor page lists SOC 2 Type II, ISO 27001, ISO 42001, AIUC-1, HIPAA compliance and PCI DSS Level 1. No certificate, auditor name, report date or scope is published on the page checked.
“Agents for Enterprise SOC 2 Type II ISO 27001 Regional Data Residency Zero Retention Mode On-prem options ISO 42001 AIUC-1 HIPAA compliant PCI DSS Level 1”
elevenlabs.io · checked Aug 18, 2026 - Regulatory alignment
- no public information
Flagged for review — the source below contains language that may address this field. Not yet checked by an editor. How we check absences
elevenlabs.io · checked Aug 3, 2026 - Outcome-based pricing
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Settlement mechanism
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Asset custody
- no public informationelevenlabs.io · checked Aug 12, 2026 · source did not state this
- Dispute process
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- SLA terms
- Enterprise tier includes SLA commitments (specific terms not published on this page).
“SLA, SSO, and enterprise access controls”
elevenlabs.io · checked Aug 3, 2026 - Evaluation coverage
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Self-reported performance
- no public informationelevenlabs.io · checked Aug 12, 2026 · source did not state this
Agency
- Autonomy level
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Human oversight
- no public informationelevenlabs.io · checked Aug 18, 2026 · source did not state this
- Goal complexity
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Action space
- Agents can automate scheduling, reminders, collections, and internal operations.
“Automate scheduling, reminders, collections, and internal ops.”
elevenlabs.io · checked Aug 3, 2026 - Operating environment
- Operates across phone, web, WhatsApp, SMS, and email channels.
“phone, web, WhatsApp, SMS, and email”
elevenlabs.io · checked Aug 3, 2026 - Initiative
- Runs outbound campaigns (lead qualification, cart recovery) -- capable of self-initiated outreach, not purely reactive.
“Qualify leads, recover abandoned carts, and run outbound at scale.”
elevenlabs.io · checked Aug 3, 2026
Safety
- Safety evaluations
- Vendor-provided guardrail configuration, simulation, and automated testing before deployment (self-administered, not stated as third-party).
“Define guardrails, run simulations, and validate agent behavior with automated tests”
elevenlabs.io · checked Aug 3, 2026 - Red teaming
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Safety policy
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Usage restrictions
- Product demo shows a guardrail blocking the agent from giving financial advice, evidencing built-in usage restrictions.
“Request blocked by guardrail”
elevenlabs.io · checked Aug 3, 2026 - Model or system card
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Incident reporting
- Publishes a vulnerability disclosure contact channel (security.txt)
“Contact: mailto:vulnerability_disclosure_program@elevenlabs.io”
elevenlabs.io · checked Aug 12, 2026 - Third-party evaluations
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Data handling
- Offers regional data residency and a zero-retention mode, plus on-prem deployment options.
“Regional Data Residency Zero Retention Mode On-prem options”
elevenlabs.io · checked Aug 3, 2026
Practicality
- Pricing model
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Price point
- Free tier includes 15 minutes of calls/text included; no further paid pricing figures published on this page.
“15 minutes included for free”
elevenlabs.io · checked Aug 3, 2026 - Availability
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Deployment options
- Offers flexible hosting including on-prem options, alongside its standard SaaS platform.
“Host and store data on your terms, anywhere”
elevenlabs.io · checked Aug 3, 2026 - Integrations
- Named integrations: Zapier, Salesforce, Stripe, HubSpot, Shopify, Zendesk, Genesys, Twilio, Amazon Connect.
“Zapier Salesforce Stripe Hubspot Shopify Zendesk Genesys Twilio Amazon Connect”
elevenlabs.io · checked Aug 3, 2026 - Supported regions
- Vendor states data residency in the US, EU, and India.
“Data residency in US, EU, and India”
elevenlabs.io · checked Aug 3, 2026 - Support model
- Enterprise tier includes Forward Deployed Engineers as part of its support model.
“Forward Deployed Engineers”
elevenlabs.io · checked Aug 3, 2026
Foundation models
- Base models
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Model provider
- LLM-agnostic; supports ElevenLabs-hosted models as well as customer-hosted models.
“LLM-agnostic - bring your own model”
elevenlabs.io · checked Aug 3, 2026 - Model swappable
- Vendor states the platform is LLM-agnostic: customers may bring their own model, call a frontier model via API, or use vendor-hosted models.
“bring your own model, call a frontier model via API, or use our hosted, domain-tunable models”
elevenlabs.io · checked Aug 18, 2026 - Open weights
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Fine-tuning
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Context window
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
Ecosystem
- Protocols supported
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Tool use
- Connects to third-party tools the customer already uses.
“connect to the tools your team already uses”
elevenlabs.io · checked Aug 3, 2026 - Multi-agent
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- API access
- Public APIs and SDKs are available: WebSocket and REST APIs, native SDKs for web and mobile.
“Native SDKs for web and mobile WebSocket and REST APIs”
elevenlabs.io · checked Aug 3, 2026 - Open source
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Marketplace presence
- no public information
Flagged for review — the source below contains language that may address this field. Not yet checked by an editor. How we check absences
elevenlabs.io · checked Aug 3, 2026
Impact
- User base
- Page displays customer logos for Twilio, The Walt Disney Studios, KPN, TVS Motor, Telus and Cisco.
“Twilio The Walt Disney Studios KPN TVS Motor Telus Cisco”
Not in our latest capture. This quote was on the page when we filed it. We captured the same page again on Sep 9, 2026 and it was not there. The value above has not been re-checked by an editor yet. How we re-check citations
elevenlabs.io · checked Aug 3, 2026 - Deployment scale
- ElevenLabs Agents reports 10M+ conversations per week
“10M+ conversations per week delivering results”
elevenlabs.io · checked Aug 18, 2026 - Target sectors
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- High-risk domains
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Documented incidents
- no public informationelevenlabs.io · checked Aug 3, 2026 · source did not state this
- Market recognition
- no public informationelevenlabs.io · checked Aug 12, 2026 · source did not state this