Security
What protects your calls and your customer list.
SiteCall handles your phone number, your call recordings, and your customers' contact details. Here is how that is protected, stated plainly — including what we don't yet claim.
Encryption
All traffic to SiteCall is served over TLS with HTTP Strict Transport Security enabled, and our connection to the database is encrypted in transit. Data at rest is encrypted at the storage layer. Access tokens for third-party services get a second layer of AES-256-GCM encryption in our application before storage, so database access alone does not yield usable credentials. Voice carried over your browser is encrypted by WebRTC, which mandates encrypted media.
Tenant isolation
Each workspace's data is separated at the database level using PostgreSQL row-level security rather than application-layer filtering alone, so a query missing a workspace filter returns nothing instead of another business's records. Automated checks in our build pipeline reject any schema change that could bypass this, and the deploy fails rather than shipping it.
Payments
We never see or store your card details. Card entry happens entirely on pages served by Stripe, a PCI-DSS Level 1 certified provider; we keep only the brand and last four digits for display. Three independent automated checks block any change that would start collecting card data on our own pages.
Access, logging, and recovery
Administrative access to production is held by the smallest number of people who need it. Reads and exports of customer data on our most sensitive endpoints are written to an append-only audit log that cannot be edited or deleted through the application. Database backups run on a schedule and are stored encrypted, off our primary hosting platform.
Policies
We maintain written information security, access control, encryption, change management, incident response, vendor management, and business continuity policies, a risk register reviewed on a set cycle, and a register of every sub-processor that touches customer data.
What we don't claim
Security pages are easy to inflate. We would rather name these than let you assume otherwise. We are not SOC 2 or ISO 27001 certified — we maintain the underlying controls and documentation, but no external auditor has attested to them. We have not completed an independent third-party penetration test.
We are not HIPAA compliant and do not sign Business Associate Agreements, so please don't put protected health information into SiteCall. And we do not offer end-to-end encryption: call recording, transcription, and AI assistance all require our systems to process your content in readable form.
Reporting a vulnerability
Email support@sitecall.ai with steps to reproduce. We aim to acknowledge reports within three business days. Please give us a reasonable window to fix an issue before disclosing it publicly, and avoid accessing accounts or data that aren't yours while testing. We don't run a paid bug bounty, and we won't pursue legal action over good-faith research that follows these guidelines.