Security

Your customers' data, treated as such

Every organisation is isolated in the database engine, not by a check somebody could forget to write. Each one gets its own phone system, not a shared space. Your systems' credentials are stored encrypted and we never copy your records: they're queried in the moment and then forgotten.

  • Isolation enforced by the database, not by the code
  • A phone system of its own per organisation
  • We audit the platform regularly
Secretos cifrados
Bóveda separada de la aplicación
Aislamiento en el motor
Impuesto en cada lectura y escritura
Registro de auditoría
Quién hizo qué, y cuándo

What we can state today

01

Isolation between organisations

Every table holding customer data carries its organisation inside it, and the engine enforces that on every read and every write. It doesn't depend on a developer remembering to check.

02

Each organisation, its own phone system

There's no shared voice server where one bad setting leaves a customer hearing another.

03

Encrypted secrets

SIP passwords, mailbox credentials and connection keys with authenticated encryption. Your systems' credentials live in a vault separate from the application.

04

Mandatory second factor

For platform administration, without exception.

05

Roles and scopes on the server

Enforced where it counts, not just by hiding buttons on screen.

06

Audit log

Of sensitive actions, with who did what and when.

07

Configurable retention

You decide how long each thing is kept. What gets deleted, gets deleted every night, without anyone having to remember.

08

Recording consent

Stored as a legal basis, not as a tick box nobody ever looks at again.

09

No copy of your systems' data

CRM queries happen in the moment and no mirror of your records is kept.

Team and permissions

Who sees what

A permission isn't a screen preference: it decides what data leaves the server.

01

Four cumulative roles

Owner, manager, supervisor and agent. Recordings and scoring aren't the agent's; team presence is supervisor and above.

02

Scope by team and by service

On top of the role: you see your own, not everything. A supervisor on one service doesn't read another service's conversations.

03

Seats counted and visible

Email invitations, with the limit always in view. Nobody discovers seats ran out just as they hit «invite».

04

Separate administration

The panel we use to set up organisations, plans and support lives on its own domain, with a mandatory second factor, and never touches the content of anyone's conversations.

Auditing

We audit the platform regularly and the report is available under a confidentiality agreement. The last full security audit was carried out in September 2026, with the fixes applied.

We do not hold ISO 27001 or SOC 2, and we're not going to imply otherwise.

What we don't publish

The number of tables, the names of the mechanisms and the topology detail are deliberately not on this page: they'd be a map for anyone looking for a way in. The how gets explained in a meeting room, under a confidentiality agreement.

Security

Data that can't leave your house?

Tell us the specific requirement and we'll tell you exactly which part can run inside your environment. Dedicated deployment exists and we've done it, but the scope depends on the case and we'd rather settle it with you than promise it on a page.

Next step

Tell us how your team works.

A straight conversation about your volume, your channels and where to start. No generic proposal.

  • We reply within 24 hours
  • 30 minutes with someone who built this
  • A concrete proposal after the first session