Security and GDPR
Data Isolation
A SaaS tenant only sees data belonging to its own account_id. Platform admin data does not leak into the customer workspace.
Keys
API keys are stored encrypted. The UI only shows a masked value. Do not share keys in support chat.
Recordings and Retention
Set retention according to your legal basis. Inform called parties as required by GDPR / local telecom law.
Outbound Compliance
- Outbound consent on leads
- Stop list (
do_not_call) - Truthful caller identification
Chatbot
In production, do not allow CORS *. Restrict origins to your own domains.