Trust Center
Security, compliance, and data practices at DialerBee
Enterprise-grade infrastructure with multi-tenant isolation, default-deny compliance, immutable audit trails, and transparent AI data practices. Built for regulated industries.
Quick answer
How does DialerBee handle security and compliance? DialerBee provides enterprise-grade security with AES-256 encryption, PostgreSQL Row-Level Security for multi-tenant isolation, immutable audit logs, and default-deny compliance controls for TCPA, GDPR, TDRA, CITC, and more. AI features are optional, off by default, and customer data is never used to train shared models.
Security
Defense in depth, not defense in hope
Every layer of the stack is hardened. Tenant isolation is validated through automated tests and security review processes, not assumed with naming conventions.
Encryption Everywhere
TLS 1.2+ for all data in transit. AES-256 encryption for data at rest. Encryption is designed to be enforced for supported production data flows, with no intended plaintext fallback.
Role-Based Access Control
7 distinct roles from agent to super_admin. API endpoints are designed to enforce role checks according to the configured RBAC model. Principle of least privilege throughout.
Multi-Tenant Isolation
PostgreSQL Row-Level Security enforced on every tenant table. Automated security testing validates that Tenant B cannot access Tenant A data.
Immutable Audit Logs
Append-only audit trail. UPDATE and DELETE revoked at the database level. Administrative and security-relevant actions are recorded with actor, timestamp, and context where audit logging is configured.
Signed Recording URLs
Call recordings are never exposed via raw paths. Signed URLs with 1-hour expiry. Expired links return 403, not stale audio.
Backup & Disaster Recovery
Automated database backups with point-in-time recovery. Recording replication to secondary storage. Tested restore procedures.
Infrastructure Monitoring
Real-time alerting on service health, latency budgets, and resource utilization. Grafana SLOs enforce 99.95% uptime per service.
Admin Activity Logging
Administrative and security-relevant actions — user creation, role change, campaign modification, configuration update — are recorded where audit logging is configured.
Compliance
Default-deny. Configured policies enforced before dialing.
Configured outbound dial paths can pass through the compliance engine before dialing. Default-deny can be enforced for configured compliance policies, blocking and logging calls that fail required checks.
DNC/DNCR Enforcement
Supports TDRA (UAE), TCPA (US), CITC (KSA), NTRA (Egypt), and TRC (Jordan) frameworks. Numbers can be checked before dialing when DNC/DNCR enforcement is configured.
Jurisdiction Calling Hours
Calling-hour rules enforced per jurisdiction. UAE default: 9:00-18:00 local, Sunday through Thursday. Fully configurable per campaign.
Consent Proof Chain
Consent records can include proof URL, IP address, user-agent, timestamp, and source. Retention policies are configurable per campaign and jurisdiction.
CLI Ownership Verification
Caller ID numbers verified per tenant per jurisdiction. No tenant can spoof another tenant's CLI. Ownership audited continuously.
Default-Deny on Failure
Configured default-deny policies can block calls when compliance checks fail, rule versions are unknown, or services return errors.
Immutable Decision Trail
Compliance decisions can be recorded with rule version, audit reference, and context where audit logging is configured. Recorded decisions are append-only.
Recording Retention Policies
Per-tenant configurable retention periods. Recordings stored according to jurisdiction requirements. Automatic expiry enforcement.
Compliance Reporting
Real-time dashboards showing block rates, DNC hit rates, consent expiry, and calling-hour violations. Exportable for regulatory audit.
AI & Data Practices
Transparent AI. Your data stays yours.
AI features are optional, off by default, and never use your audio to train shared models. Full human override at every step.
Minimal Audio Processing
AMD classification is designed to process a short initial segment of call audio. Full-call audio analysis is not performed without explicit opt-in. Detailed AI data policy available on request.
No Long-Term Transcript Storage
Transcripts generated for AMD classification are used in real time and are not stored long-term. Classification results are retained; raw transcripts are not.
Per-Tenant Model Training
AMD feedback can be tenant-scoped and governed by customer retention and AI settings. No cross-pollination between tenants by default.
No Shared Model Training
Customer call data is not used to train shared cross-tenant models by default. AMD feedback can be tenant-scoped and governed by customer retention and AI settings.
Off by Default
AI features can be controlled by tenant-level feature flags and opt-in settings. Nothing activates without explicit tenant configuration.
Human Override Always Available
Agents can override any AI classification at any time. AI assists; humans decide. Automated decisions are always reviewable.
Full Opt-Out Available
Tenants can disable all AI features entirely with a single configuration change. The platform operates at full capability without AI.
AI Decision Audit Trail
AI classifications can be logged with confidence score, model version, and human override status where audit logging is configured.
Data Residency & Storage
Know exactly where your data lives
All data is tenant-isolated at every layer. Storage locations and retention policies are configurable per tenant to meet jurisdiction requirements.
Private Cloud Recording Storage
Call recordings are stored in MinIO on private cloud infrastructure. No third-party object storage. Full control over data locality and access policies.
PostgreSQL for Structured Data
All structured data — contacts, campaigns, compliance decisions, audit logs — stored in PostgreSQL 16 with Row-Level Security enforced on every tenant table.
Redis for Ephemeral Data
Session data, real-time agent state, and caching use Redis. Ephemeral by design. No persistent customer data stored in cache layers.
Complete Tenant Isolation
Controls are designed to prevent cross-tenant data access, with row-level security, scoped tokens, and automated security testing.
Configurable Retention
Recording retention, audit log retention, and data lifecycle policies are configurable per tenant. Automatic enforcement of retention windows.
Encrypted at Every Layer
Data encrypted in transit between all services (mTLS). Encrypted at rest in PostgreSQL, MinIO, and backup storage. Key management follows industry best practices.
Compliance disclaimer
DialerBee provides compliance-supporting tools, configurable controls, audit logs, and enforcement workflows designed to help organizations meet regulatory requirements. Customers remain responsible for their own legal compliance and should consult qualified counsel for jurisdiction-specific requirements. Regulatory frameworks referenced (TDRA, TCPA, CITC, NTRA, TRC) are subject to change.
Security posture
Current implementation status of our security program
Security Resources
Documents & policies
Download or request security documentation for your review.
Security Overview
Architecture, encryption, access controls, and infrastructure details.
Request PDFData Processing Agreement
Standard DPA for data controllers. GDPR-aligned terms.
Request DPASubprocessor List
Third-party services that process data on our behalf.
View ListAI Data Policy
How AMD processes audio, training scope, and opt-out options.
View PolicyVulnerability Disclosure
Report security issues responsibly. We respond within 48 hours.
Report IssuePenetration Test Summary
Summary of latest pen-test findings. Available under NDA.
Request SummaryPrivacy Policy
How we collect, use, store, and protect personal data.
Read PolicyTerms of Service
Usage terms, acceptable use, liability, and agreements.
Read TermsIncident Response Policy
How we detect, respond to, and communicate security incidents.
Request DetailsFor enterprise security packs, custom DPAs, or compliance questionnaires, contact security@dialerbee.com
Last updated: June 2026 · SOC 2 Type II: Planned
Questions about security or compliance?
Our team is ready to discuss your requirements, share documentation, and walk through our security practices.