Skip to content

Security

Security, compliance and responsible AI you can check yourself.

The controls that protect your account and data across phone, dialer, SMS and email, the compliance checks that run before each call, and the rules our AI works within.

Controls

What protects your account and data

Built into every workspace, on every plan.

Account security

  • Two-factor authentication

    Protect sign-in with a code from an authenticator app.

  • Trusted IPs and sign-in approvals

    Restrict sign-in to allow-listed IP addresses, and approve sign-in attempts from anywhere else.

  • Role-based permissions

    Give each user only the areas and actions their role needs.

  • Login history

    See who signed in, and when.

Platform

  • A separate database per customer

    Your leads, call records, messages and settings are kept apart from every other customer's.

  • Signed outbound webhooks

    Standard Webhooks with HMAC-SHA256 signatures and up to 9 retries, so your systems can verify every request.

  • Webhook secrets encrypted at rest

    Signing secrets are stored encrypted.

  • A ledger for every credit

    Each top-up, trial grant and usage charge is recorded in an append-only ledger you can review under Billing.

  • A reference ID on every API response

    Quote it to us and we can trace the exact request.

  • Security headers, including HSTS

    Browsers are told to use HTTPS for every visit.

Data isolation

Where your data lives

Each customer gets a separate database, so your leads, call records and messages are never stored alongside another customer's.

Your teambrowser · HTTPS
Phonify app and APIsigns you in, routes to your database
  • Your databaseonly your workspace
  • Customer Bseparate database
  • Customer Cseparate database
Your team reaches Phonify over HTTPS. The app signs you in and connects you to your workspace's own database; other customers' data lives in databases of their own.

Responsible AI

AI that discloses first and hands off to people

How voice AI agents and AI call review treat your callers and your data.

  • Disclosure first

    Outbound AI calls open with a disclosure that the caller is speaking to an AI assistant, in your words or our default, plus a recording notice. Each agent keeps its own disclosure text.

  • A person is one step away

    Give the agent a warm or cold transfer to a user, ring group or number, and it hands the call to your team mid-conversation.

  • Only the lead fields you allow

    By default the AI sees a lead's name, company, city and state. Phone numbers, emails, SSNs, dates of birth and card or account numbers are always held back, whatever the settings.

  • Redacted transcripts

    AI call review redacts card numbers, Social Security numbers and other spoken numbers from the transcript before it is stored.

  • Versioned prompts

    Every prompt change is saved as a version you can review, and you can roll back to an earlier one at any time.

  • Scored for compliance

    The QA scorecard includes a compliance category and records whether the disclosure was given.

Calling compliance

Compliance checks that run before every call

Phonify provides the tools. Compliance with TCPA and carrier rules remains your responsibility.

  • Consent ledger

    Record the consent behind each contact and check it before you reach out.

  • Internal and national DNC

    Your own do-not-call list and the national registry are checked before each call.

  • Local calling hours

    Dial only within the lead's local calling hours, 8am–9pm by default.

  • STOP / START / HELP replies

    Opt-out and help keywords on SMS get an automatic reply.

  • AI and recording notices

    An AI disclosure plays before the AI speaks, and recording notices are built in.

  • E911 address capture

    An emergency address is captured for each user.

Compliance roadmap

Where we are, stated plainly

We assess ourselves against OWASP ASVS Level 2. SOC 2 readiness is next. Ask us for our current status.

Ask for our current status

Responsible disclosure

Found a security issue?

Tell us through the contact form with the topic set to Security. Include what you found and the steps to reproduce it, and give us a reasonable time to fix it before sharing it publicly.

Report a vulnerability

Please do not access other customers' data or disrupt the service while testing.

Open the security form

Security questionnaires

Evaluating Phonify for your company? Send us your questions. We reply by email.

Ask a security question

See the controls for yourself.

Start a trial, turn on two-factor authentication and trusted IPs, and route a number to an AI agent that discloses first.

14-day trial · no credit card · set up in the browser