Retell AI published a PII redaction feature today, letting agencies mask customer personal data from call transcripts and logs. It's a solid compliance move. But here's the thing: agencies shouldn't have to bolt compliance onto their infrastructure. It should be baked in from day one.
Why This Matters for AI Voice Agencies
For the past 18 months, voice AI platforms have competed on speed and latency. "How fast is your agent?" and "Does it sound human?" were the only questions people asked.
That's changing. Agencies now ask: "Can I legally run this call?" and "What happens if a call gets leaked?"
Here's the sequence most agencies follow:
- They build an agent on Retell or VAPI
- They add GoHighLevel for CRM integration
- They stitch in Zapier to hide certain data fields
- They add Stripe for billing
- They hire a developer to glue it all together
- They realize compliance falls through the cracks
- They add a PII redaction layer (like Retell's new feature)
- They add call recording governance
- They add consent management
This is tooling hell. And compliance is too important to be the last thing you add. When the FTC sends a warning letter (they've sent 15 so far in 2026), it's because compliance wasn't baked in.
What We're Doing at Hermes
Hermes is built for regulated use from day one. Your white-label voice agents don't just work. They work safely.
Here's what's built in:
- PII redaction and masking: Automatic at call time. No feature you add later.
- Call recording governance: TCPA-compliant recording, storage, and retention. Built into the platform.
- Consent management: Prior express consent tracking across calls and campaigns. No extra layer.
- Compliance audit trail: Every call logged with retention policies baked in. Your clients see what they need to see.
- White-label compliance: Your clients get compliance as part of your service. Not as an upsell.
Retell's PII redaction is a feature. The Hermes compliance layer is a foundation. One is bolted on. The other is load-bearing.
Action Steps for Agencies Right Now
1. Audit your current call stack for compliance gaps.
If you're using Retell, VAPI, or any voice engine plus a separate CRM plus Zapier, you likely have compliance blind spots. PII redaction on the voice layer doesn't mean your CRM is handling it right. Check your integration points.
2. Map out your regulatory exposure.
What industry are your clients in? Insurance, healthcare, financial services, real estate all have different rules. TCPA applies to everyone. State deepfake laws apply to voice. The FTC is actively sending warning letters. Compliance isn't optional anymore.
3. Ask your platform: "What happens if someone asks to hear this call?"
If your answer is "we'd have to go pull it from five systems," you're exposed. Retell's new feature helps on one vector. But compliance is end-to-end. Can you produce a call? Can you redact it? Can you prove you got consent? If any of those answers require manual work, you're not really compliant.
4. Price in compliance from the start.
Don't compete on raw price. Charge for regulated, compliant use. Agencies that own compliance own margin. Charge more, deliver certainty.
5. Test your stack with a regulator in mind.
Before you sell voice AI to your next client, run one call through your entire stack and ask: "Could I explain this to the FTC?" If the answer is no, fix it first.
How the Platforms Compare
Retell's update is good. But it's one piece of a much bigger puzzle. Here's how the platforms stack up:
| Feature | Retell + DIY Stack | Synthflow | Hermes |
|---|---|---|---|
| Voice engine | Yes (Retell) | Yes | Yes (integrated) |
| PII redaction | Yes (new) | No | Yes (built-in) |
| CRM | No (use GHL) | No | Yes (built-in) |
| Call recording governance | No | No | Yes (built-in) |
| Consent management | No | No | Yes (built-in) |
| White-label pricing | $0.13-0.33/min (infrastructure tax) | $3,400+/mo (enterprise) | $149-699/mo (all-in) |
| Integration cost | $8K-15K developer time | High (needs setup) | Day 1 live |
FAQs
Q: Isn't Retell's new PII redaction enough?
No. PII redaction is one layer. You also need call recording governance, consent tracking, retention policies, and audit trails. Retell handles the voice layer; you still have to solve compliance at the CRM, database, and backup levels. Hermes handles all of it.
Q: Do I need to be in a regulated industry to care about compliance?
Yes. The FTC and FCC regulate AI-powered calling for everyone. TCPA applies to all outbound calls. State deepfake laws apply to voice cloning. Compliance is not optional, and it's not industry-specific.
Q: Can I just add Retell's PII redaction and call myself compliant?
No. You also need to prove you got prior express consent, that you're handling call recordings securely, that you can produce a call on request, and that you're following retention policies. One feature doesn't make a compliance stack.
The Bottom Line
Retell's PII redaction is a solid move. It shows the platform is maturing. But agencies shouldn't have to bolt compliance onto their infrastructure. When you're selling voice AI to clients, compliance should be load-bearing from day one.
That's how BuildWithHermes is built. And that's where agencies find margin.
Ready to own compliance and margin? Start with Hermes on the Starter plan at $149/mo (Business $399/mo, Agency $699/mo, Pro is Contact Us). First agent live in 72 hours. See buildwithhermes.com.
Sources
- Retell AI: PII Redaction and Toll-Free Features (X, 08-20-2026)
- IAPP: How the FCC and FTC Regulate AI-Powered Robocalls
Originally published at buildwithhermes.com/blog/retell-pii-redaction-compliance-2026-08-20.
Top comments (0)