Security built into every conversation
Encryption in transit and at rest, least-privilege access, audited admin actions, PCI-DSS payments, and HIPAA support — working in real time behind every voice and chat agent.
Last updated: January 19, 2026
Traffic encrypted
100%
Threats blocked (30d)
1,284
MFA on admin
Enforced
Monitored uptime
99.9%
Active controls
- TLS / HTTPSOn
- AES-256 at restOn
- Role-based accessOn
- Audit loggingOn
- Threat scoringOn
- Webhook signingOn
Live event stream/var/log/security
Illustrative view of platform controls. Live availability is published on our status page.
Defense in depth, by default
Layered controls span the network, application, data, and AI behavior — so security isn't a setting you have to remember to turn on.
Encryption everywhere
TLS/HTTPS for every byte in transit and AES-256 for data at rest across our cloud infrastructure.
Least-privilege access
Role-based access controls, MFA-enforced admin sign-in, and minimum-necessary permissions by job function.
Audited & monitored
Administrative actions are logged for monitoring and audit, with security events shipped to forensic storage.
Threat prevention
Real-time risk scoring, rate limiting, abuse auto-blocking, and disposable/bot lead filtering at the edge.
Hardened infrastructure
Isolated production databases, restricted access, and regular dependency updates and security patching.
Responsible AI
Policy guardrails, grounded responses, and human-in-the-loop escalation options for sensitive use cases.
Standards we align to
We map our program to the frameworks that matter to regulated industries, and provide documentation to your security team on request.
- PCI DSS: Card payments are handled by PCI DSS compliant processors (e.g., Stripe); we do not store card data on our servers.
- HIPAA: HIPAA support is available for healthcare customers with a signed BAA and eligible infrastructure configuration. Contact us for details.
- GDPR & CPRA: Our practices are designed to align with GDPR and CPRA, and we support data-subject rights requests (access, delete, export). A Data Processing Addendum (DPA) is available for business customers.
- TCPA:Our platform is designed to support customers' TCPA compliance (e.g., consent and opt-out handling); customers remain responsible for their own calling practices.
For the third-party providers that process data on our behalf, see our Subprocessors page, and our Privacy Policy for data-handling details.
Controls, in depth
The specifics behind each layer — written for the security reviewer, not just the buyer.
Data encryption
- In transit: All data transmitted to and from our services is encrypted using TLS/HTTPS.
- At rest: Customer data is encrypted at rest on our cloud infrastructure (AWS, Vercel) using industry-standard AES-256 encryption.
Access controls
- Role-based access: Access to customer data is restricted to authorized personnel based on job function.
- Admin logging: Administrative actions are logged for security monitoring and audit purposes.
- Least privilege: Team members are granted the minimum access necessary to perform their duties.
Infrastructure security
- Cloud hosting: Our services are hosted on reputable cloud providers (AWS, Vercel) that maintain their own security certifications.
- Database security: Production databases are isolated and access is restricted.
- Regular updates: We regularly update dependencies and apply security patches.
Payment security
Payments are processed by PCI-DSS compliant providers (e.g., Stripe). We do not store credit card numbers, CVVs, or other sensitive payment details on our servers. All payment data is handled directly by our payment processor.
AI & data handling
- Third-party AI providers: We use OpenAI and other AI providers to power our voice and chat agents. Data sent to these providers is subject to their respective privacy policies.
- Guardrails: We implement guardrails to help keep AI responses on-topic and within defined boundaries.
- Human-in-the-loop: Options for human review and escalation are available for sensitive use cases.
- Response verification: AI responses may require verification for critical actions. We do not guarantee error-free AI outputs.
Security documentation
The following artifacts are available to prospective and current enterprise customers on request, under NDA where applicable:
- Completed security questionnaires (e.g., SIG Lite, CAIQ)
- Summary of our most recent third-party penetration test
- Data Processing Addendum (DPA) and subprocessor list
Incident response
In the event of a security incident affecting customer data, we will notify affected customers in accordance with applicable laws and our contractual obligations.
Responsible disclosure
Found a vulnerability? Report it to support@callsphere.ai. We appreciate responsible disclosure and will work with you to address any valid security concerns.
Security requests
For enterprise security questionnaires or to request the documentation above, email support@callsphere.ai.
Ready to transform your business workflow?
Book a 30-minute walkthrough to see how CallSphere AI agents reduce costs, cut response times, and improve customer satisfaction.