AI Voice Agents are live on our Tier 2 rails at $0.10 per minute. See the product
Trust

Security

Voice traffic carries health details, payment details, and identifiers, and a telephony credential is a path onto the PSTN. Here is what protects both, stated without a badge we have not earned.

Controls at a glance

Six things that are true of every account, not of a premium tier.

Encryption, included

Media and storage encryption are on by default at no additional charge. It is not an add-on line on the rate card and there is no version of the account where it is off.

Redaction, included

Personally identifiable information and payment data are redacted from transcripts at no additional charge, so the stored artifact does not carry a card number nobody needed to keep.

Sub-account isolation

Each sub-account carries its own numbers, trunks, routing, and credentials. A token scoped to one tenant cannot read another, and CDRs roll up without cross-tenant visibility.

Credential handling

Bearer tokens scoped to an account and revocable on their own, per-trunk SIP credentials with their own access control lists, and IP allowlists at the network edge.

Toll fraud controls

Velocity limits, destination allowlists, spend caps, and anomaly alerting. A compromised credential costs a bounded number instead of an unbounded one.

Signed calls and records

STIR/SHAKEN signing with the attestation level your traffic earns, and traceback answered from CDRs and recordings rather than reconstructed from memory.

Encryption and redaction are included, not upsold

Recording runs in the network rather than in your application, which means the protections around it are ours to guarantee rather than yours to remember.

  • Encryption at no charge. Media and storage encryption are on by default. The rate card lists encryption at no charge rather than leaving it off the card.
  • Redaction at no charge. Transcript redaction of personal and payment data is included, alongside transcription at $0.05 per minute.
  • Time-limited access. Playback and download run on signed URLs that expire, so a link pasted into a chat does not become a permanent door.
  • Delete means delete. Deleting a recording removes the media. The CDR that references it is kept on the separate schedule billing records need.
  • Consent is yours. Recording announcements and two-party consent are your obligation and belong in the call flow. See turning recording on.
A glass audio waveform sculpture lit from within

Access control and credentials

Two credential families guard two different doors. Both are scoped narrowly enough that losing one does not mean losing the account.

On the network

  • Per-trunk SIP credentials, each with its own access control list.
  • IP allowlists enforced at the edge, so unauthenticated sources never reach call processing.
  • Calls presenting a From number the account does not own are rejected.
  • Destination prefix restrictions per trunk, so a trunk built for domestic traffic cannot reach a premium international range.

On the API

  • Bearer tokens scoped to an account, restrictable to read-only or to a subset of resources.
  • Separate tokens per service, so rotating one is a deploy rather than an outage.
  • Sub-account scope is a property of the token, not a parameter a caller can change.
  • Signed webhook deliveries with a timestamp tolerance, so a captured payload cannot be replayed at you later.

Toll fraud and spend protection

Toll fraud is the attack that actually happens to telephony accounts. It is fast, it is automated, and it goes straight for the expensive destinations. The defense is a ceiling set in advance.

  • Destination allowlists. Restrict which country codes and prefixes an account can dial at all. This is the single most effective control, and the one most often skipped.
  • Velocity limits. Cap calls per minute to a destination or a prefix, so an automated dialer running on stolen credentials is throttled within seconds.
  • Spend caps. Stop an account or a sub-account outright at a threshold you set, per day or per period.
  • Anomaly alerting. A pattern break, such as sudden volume to a range the account has never dialed, raises an alert on our side as well as yours.
  • Fast revocation. A trunk credential or an API token can be revoked on its own without taking the rest of the account with it.

Set these before go-live

Allowlist
The country codes and prefixes you actually call. Everything else rejected.
Velocity
Calls per minute per destination, sized to your real peak plus headroom.
Spend cap
A daily ceiling per account and per sub-account, set to a number you could absorb.

Identity, traceback, and retention

Holding carrier interconnects means holding obligations. These three are the ones that show up in writing.

STIR/SHAKEN signing and attestation

Outbound calls are signed, and the attestation level reflects what we can actually verify: that the call came from a known customer and that the calling number belongs to them. We do not sell A-level attestation on traffic that has not earned it, because the point of the framework is that the attestation means something. Attestation is carried on the CDR so you can see what downstream carriers saw.

Traceback and complaint response

When an industry traceback request or a carrier complaint arrives, it is answered from records: the CDR for the leg, the route and carrier that carried it, the attestation applied, and the recording where one exists. We will tell you when your traffic is the subject of one, and what we sent. Persistent illegal traffic gets an account disconnected, which is the obligation that comes with holding carrier interconnects.

Retention you set

Retention windows are configured per account for recordings, transcripts, and records, so regulated audio ages out on your schedule rather than ours. Call detail records carry customer proprietary network information; access to them is restricted and logged, and deleting a recording leaves the CDR that references it on its own separate schedule.

Recording, transcription, attestation, and CDR retention are described in full on the recording and compliance page.

Compliance program

We would rather be believed about a smaller claim than doubted about a larger one, so this section says exactly where the program stands.

What you can get today: a completed security questionnaire, a written description of the control set, the encryption and retention specifics that apply to your account, and a conversation with the engineers who operate it. Ask at contact@solvedtele.com.

Incident response and disclosure

Two commitments: you hear about an incident from us, and a researcher who finds something hears back from us.

  • You hear it from us. Service incidents are posted to your shared support channel and to the status page, with an update at least every 60 minutes while one is open.
  • Security incidents are different. If an incident affects your data, you get a direct notification naming what was affected and what we did, not a line on a status page.
  • Evidence, not narrative. Post-incident, you can have the CDRs, the SIP traces, and the timeline for the affected window.
  • Planned work is announced. Maintenance gets at least 72 hours of notice and runs outside United States calling hours.

Responsible disclosure

If you believe you have found a vulnerability in our network, our API, or our sites, email contact@solvedtele.com with a subject line starting "Security" and enough detail to reproduce the issue. We acknowledge reports within one business day, keep you updated while we work, and will credit you when a fix ships if you want the credit.

In return we ask that you give us a reasonable window to fix the issue before disclosing it publicly, that you do not access, modify, or retain data belonging to anyone else, and that you do not degrade service for other customers while testing. Please do not run load tests, place fraudulent calls, or send unsolicited messages through the network as part of a test. We will not pursue legal action against researchers acting in good faith within those terms.

Security questions from a procurement process are welcome at the same address. Send the questionnaire and we will complete it.

FAQs

Security questions

Are you SOC 2 certified?

No, and we will not imply otherwise. There is no completed SOC 2 report, no named auditor, and no certificate behind this page. Formal audit readiness work is underway: control documentation, evidence collection, access reviews, and vendor review. When an audit is complete we will say so here plainly and make the report available under NDA.

Are you HIPAA compliant?

We have not completed a HIPAA audit or attestation and do not claim one. What we can describe is the control set: encryption on by default, transcript redaction at no charge, retention windows you set, restricted and logged access to recordings, and sub-account isolation. If your use case involves protected health information, tell us during onboarding so we can talk through what we can and cannot support today.

Does encryption cost extra?

No. Media and storage encryption are on by default at no additional charge, and transcript redaction is free as well. They are listed on the rate card at no charge rather than omitted from it, so there is no ambiguity about what you are paying for.

What happens if my SIP credentials are stolen?

The blast radius is what you configured before it happened. Destination allowlists stop traffic to the expensive international ranges fraud targets first, velocity limits cap calls per minute, and spend caps stop the account outright at a threshold you set. Anomaly alerting flags a pattern break. Set all three before go-live; they are the difference between a small number and a large one.

Who can listen to our recordings?

Access is restricted to the account and sub-accounts that own the call, and to the engineers who need it to work a specific issue. Playback links are time-limited signed URLs rather than permanent addresses. If you want a shorter retention window than the default, set it; the quickest way to reduce exposure on stored audio is to keep less of it.

How do I report a vulnerability?

Email contact@solvedtele.com with the subject line starting "Security". Include enough detail to reproduce the issue. We acknowledge reports within one business day and will not pursue legal action against researchers who act in good faith under the disclosure terms on this page.

Something else? Contact us

Need the details in writing?

Send your questionnaire and we will complete it, including the parts where the honest answer is not yet.