Skip to content
CallCeptorv0.7.3
Open menu

Security and compliance

Answers for your CISO and compliance officer

Financial firms review a call vendor the way they review any system that holds client data. This page covers what they usually ask. The full vendor pack is sent at the start of an enterprise trial.

Data residency

  • Tenant data, call records, recordings, transcripts and backups are stored in Indian cloud regions.
  • Encryption keys are managed in India, one key per tenant.
  • Sub-processors are listed in the vendor pack, with the region each one uses.

Encryption

  • Call audio is encrypted in transit with DTLS-SRTP, the WebRTC standard.
  • All other traffic uses TLS 1.2 or later.
  • Data at rest, including recordings, is encrypted with AES-256.

Recording and retention

  • Recording policy per department: off, on with consent, or always on.
  • A tamper-evident hash is stored for every recording; write-once storage is available.
  • Retention period per department, with automatic, logged deletion.
  • Legal hold per call or per client, which overrides deletion.
  • Export includes chain-of-custody metadata.

Access control and audit

  • Roles: Owner, Admin, Compliance, Supervisor, Agent. Compliance is read-only for recordings and audit logs.
  • Two-factor sign-in for every user; IP allow-listing for the console.
  • Every admin change, routing change, and recording playback or download is written to the audit log.
  • SSO (SAML, OIDC), SCIM provisioning and SIEM export are coming next.

Visitor privacy

  • Consent for recording and data processing is collected before the call.
  • Page, referrer and campaign data are captured only after consent.
  • Per-lead export and deletion for data requests, respecting legal holds.

Vendor due diligence

  • A security pack with questionnaire answers, architecture and data-flow diagrams, and a SEBI CSCRF mapping.
  • Third-party VAPT once a year, with a summary shared under NDA.
  • Software bill of materials on request. ISO 27001 and SOC 2 are on the roadmap.

Setting a recording policy? Our guide on recording policy per department lists the decisions to make first.

Security questions

Does call audio pass through servers outside India?

No. Media servers, relays and recording storage run in Indian regions, so audio between an Indian visitor and an Indian agent stays in the country.

Can our compliance team review calls without being able to change anything?

Yes. The Compliance role can search and play recordings and read the audit log, but cannot change routing, users or retention. Their playbacks are logged too.

How do you handle a regulator or court asking for recordings?

Place a legal hold on the calls or client, then export. The export includes each recording's hash and its access history, so you can show it hasn't been altered.

Start your security review in parallel with a pilot.

We send the vendor pack on day one, so the review and a single-department pilot run at the same time.