VoDialer AI

Security

How VoDialer AI protects your data and your calls, and what is not done yet.

Last updated 6 October 2026

VoDialer holds sensitive material: phone numbers, consents, recordings, transcripts and, in Medicare calls, health-adjacent facts. This is a short, honest summary of how we protect it. The full threat model and findings are in our internal security document, which we share with customers under NDA.

What is in place

  • Each company sees only its own data. The database shows every query only that company’s rows (row-level security), and the services check again. We test this by running every API operation against another company’s identifiers and every role against every operation.
  • Encryption. Traffic is encrypted in transit at the edge. Passwords and API keys are stored only as hashes. Carrier passwords, connector secrets, authenticator secrets and any field a bot marks sensitive (such as a Medicare number) are encrypted at rest with AES-256-GCM. Phone numbers in the do-not-call and consent records are stored as keyed hashes.
  • A tamper-evident audit. Every sensitive action is written to a hash-chained log that can be verified. Reading a recording, a transcript, or a live call is logged before anything is returned, and refused if it cannot be logged.
  • Sign-in. Passwords are hashed with argon2id, wrong guesses lock the account for a growing delay, sessions end after 12 idle hours, and changing a password signs the person out everywhere. An authenticator-code second step is available, and is mandatory for our own platform operators.
  • Least access for our staff. Platform operators can look at a customer’s company only in a read-only, time-limited session that the customer’s own audit log records.
  • Logs without personal data. Logs carry no full phone numbers, names, dates of birth, Medicare or Social Security numbers, tokens or transcript text.
  • Small attack surface. In production only the web edge is exposed to the internet. The data stores and internal services sit on private networks.
  • Dependencies. Locked and audited, with images pinned by digest.

What is not done yet

We would rather you read this here than find it later.

  • Dates of birth are not yet encrypted at rest. They are masked by role in the product and exports.
  • Nothing deletes recordings or transcripts automatically yet. Retention dates are recorded, but the deletion job and a documented erasure procedure are still to be built.
  • Encryption keys are single platform keys. There are no per-company keys and no key-rotation job for encrypted fields yet.
  • Services trust each other through a shared secret and network isolation. Per-service keys or mutual TLS are planned.
  • No single sign-on yet.
  • No independent penetration test yet. It is planned before the first customer goes live.
  • The platform has been exercised on a simulated phone network, not yet on real carriers.

Report a problem

If you find a vulnerability, please tell us privately at hello@vodial.ai. Include what you did, what you saw, and whether you kept any data. We acknowledge within one working day, give a first assessment within three, and fix problems that expose another company’s data first. Please do not test against other people’s accounts or real data. Nobody is penalised for reporting in good faith.