Skip to main content

Security practices

Practical safeguards for voice-agent operations

This page describes current product practices, not a claim of a specific certification. Contractual security requirements should be documented separately for each commercial relationship.

Authenticated product access

The application dashboard requires authenticated access. Application-level Admin operations are authorized by the backend rather than relying only on client-side navigation.

Server-side provider credentials

Telephony and infrastructure credentials are configured on the server and are not embedded in public landing-page code or browser environment variables.

Provider-aware validation

Supported purchase workflows can validate downstream organization configuration before initiating a provider operation that may create a charge.

Operational visibility

Call history and scheduled activity views provide operational records inside the authenticated dashboard.

Dependency maintenance

The application is tested with TypeScript, linting, production builds, and production dependency audits as part of security maintenance.

Documented commitments

Security certifications and contractual commitments are represented only when they have been formally completed and documented in writing.

Responsible deployment

Customers remain responsible for lawful calling permissions, recording and AI disclosures, data minimization, contact-list rights, and appropriate human oversight in every operating region.