Retell AI published a PII redaction feature today, letting agencies mask customer personal data from call transcripts and logs. It's a solid compliance move. But here's the thing: agencies shouldn't have to bolt compliance onto their infrastructure. It should be baked in from day one.
For the past 18 months, voice AI platforms have competed on speed and latency. "How fast is your agent?" and "Does it sound human?" were the only questions people asked.
That's changing. Agencies now ask: "Can I legally run this call?" and "What happens if a call gets leaked?"
Here's the sequence most agencies follow:
This is tooling hell. And compliance is too important to be the last thing you add. When the FTC sends a warning letter (they've sent 15 so far in 2026), it's because compliance wasn't baked in.
Hermes is built for regulated use from day one. Your white-label voice agents don't just work. They work safely.
Here's what's built in:
Retell's PII redaction is a feature. Hermes' compliance layer is a foundation. One is bolted on. The other is load-bearing.
If you're using Retell, VAPI, or any voice engine + a separate CRM + Zapier, you likely have compliance blind spots. PII redaction on the voice layer doesn't mean your CRM is handling it right. Check your integration points.
What industry are your clients in? Insurance, healthcare, financial services, real estate all have different rules. TCPA applies to everyone. State deepfake laws apply to voice. The FTC is actively sending warning letters. Compliance isn't optional anymore.
If your answer is "we'd have to go pull it from five systems," you're exposed. Retell's new feature helps on one vector. But compliance is end-to-end. Can you produce a call? Can you redact it? Can you prove you got consent? If any of those answers require manual work, you're not really compliant.
Don't compete on raw price. Charge for regulated, compliant use. Agencies that own compliance own margin. Charge more, deliver certainty.
Before you sell voice AI to your next client, run one call through your entire stack and ask: "Could I explain this to the FTC?" If the answer is no, fix it first.
Retell's update is good. But it's one piece of a much bigger puzzle. Here's how the platforms stack up:
| Feature | Retell + DIY Stack | Synthflow | Hermes |
|---|---|---|---|
| Voice engine | Yes (Retell) | Yes | Yes (integrated) |
| PII redaction | Yes (new) | No | Yes (built-in) |
| CRM | No (use GHL) | No | Yes (built-in) |
| Call recording governance | No | No | Yes (built-in) |
| Consent management | No | No | Yes (built-in) |
| White-label pricing | $0.13-0.33/min (infrastructure tax) | $3,400+/mo (enterprise) | $149-699/mo (all-in) |
| Integration cost | $8K-15K developer time | High (needs setup) | Day 1 live |
No. PII redaction is one layer. You also need call recording governance, consent tracking, retention policies, and audit trails. Retell handles the voice layer; you still have to solve compliance at the CRM, database, and backup levels. Hermes handles all of it.
Yes. The FTC and FCC regulate AI-powered calling for everyone. TCPA applies to all outbound calls. State deepfake laws apply to voice cloning. Compliance is not optional, and it's not industry-specific.
No. You also need to prove you got prior express consent, that you're handling call recordings securely, that you can produce a call on request, and that you're following retention policies. One feature doesn't make a compliance stack.
Retell's PII redaction is a solid move. It shows the platform is maturing. But agencies shouldn't have to bolt compliance onto their infrastructure. When you're selling voice AI to clients, compliance should be load-bearing from day one.
That's how Hermes is built. And that's where agencies find margin.
Ready to own compliance and margin? Start with Hermes on the Starter plan ($149/mo). First agent live in 72 hours. Or see how Hermes compares to Retell.