Security
Security
How the platform handles your data, what we can demonstrate today, and — just as usefully — what we do not yet claim.
- Effective 2026-08-19
Last updated
Where the service runs
The public website is a static export served from Cloudflare's edge network, which also provides TLS termination and DDoS protection. The application and its API run separately from the marketing site, and the two share no credentials.
Data in transit
- All web and API traffic is served over HTTPS. Plain HTTP requests are redirected.
- Signalling to our carrier is encrypted, and media can be encrypted end to end where the carrier and endpoint both support it.
- Browser softphone media uses WebRTC, which encrypts media by default.
Payments
Card details are entered directly with Stripe and never traverse or rest on our servers. We store a payment method reference and the billing records needed for invoicing, nothing more. Wallet balances are held in an append-only double-entry ledger, so every movement is attributable and no balance can be silently rewritten.
Access control
- Customer data is isolated per workspace, and every query is scoped to the workspace of the authenticated session.
- Roles determine what a team member can see and do, including who can access recordings and billing.
- Administrative access to production is limited to the people who need it, and is used for support and incident response rather than routine work.
Recordings and transcripts
Recording is off unless you enable it. When enabled, recordings are stored through our carrier and referenced from your workspace; transcripts are generated by the speech provider listed below and stored with the call. You control retention, and deleting a recording deletes it from our systems and instructs deletion at the carrier.
Sub-processors
The full list, with what each one does and what it receives, is in the data processing addendum. In summary:
- Twilio — Carrier connectivity: placing and receiving calls, sending and receiving SMS, renting phone numbers, and storing call recordings.
- Stripe — Payment processing for wallet top-ups and subscriptions.
- Deepgram — Speech-to-text for live transcription and AI voice agents.
- Anthropic — Language model reasoning for AI voice agents and call insights.
- Cloudflare — Hosting, CDN and DDoS protection for the public website and application.
- Kudos CRM — Routing early-access and sales enquiries to the team that answers them.
Abuse and fraud controls
- Rate limiting on public endpoints, including the early-access form, which is also honeypot-protected.
- Wallet balances stop outbound traffic at zero, which caps the financial exposure of a compromised account.
- Traffic monitoring for the patterns that indicate toll fraud and traffic pumping.
What we do not claim
We do not currently hold SOC 2, ISO 27001 or HIPAA certification, and we will not imply otherwise on a sales call. Several customers operate in regulated sectors and we support them with configuration, contractual commitments in the data processing addendum, and honest answers about where we are.
If a certification is a hard requirement for you, tell us during evaluation rather than after. We would rather lose the deal than misrepresent the position.
Reporting a vulnerability
If you believe you have found a security issue, contact us with the details and, if you can, steps to reproduce it. Please give us a reasonable window to fix it before disclosing publicly. We will acknowledge your report, keep you updated, and credit you if you would like to be credited. We will not pursue legal action against good-faith research that respects user privacy and does not degrade the service.
Questions about any of this?
Policy questions go to a person, not a ticket queue. Ask before you sign anything, and we will answer in writing.