Trust Center

Security, compliance, and data practices at DialerBee

Enterprise-grade infrastructure with multi-tenant isolation, default-deny compliance, immutable audit trails, and transparent AI data practices. Built for regulated industries.

Quick answer

How does DialerBee handle security and compliance? DialerBee provides enterprise-grade security with AES-256 encryption, PostgreSQL Row-Level Security for multi-tenant isolation, immutable audit logs, and default-deny compliance controls for TCPA, GDPR, TDRA, CITC, and more. AI features are optional, off by default, and customer data is never used to train shared models.

Security

Defense in depth, not defense in hope

Every layer of the stack is hardened. Tenant isolation is validated through automated tests and security review processes, not assumed with naming conventions.

Encryption Everywhere

TLS 1.2+ for all data in transit. AES-256 encryption for data at rest. Encryption is designed to be enforced for supported production data flows, with no intended plaintext fallback.

Role-Based Access Control

7 distinct roles from agent to super_admin. API endpoints are designed to enforce role checks according to the configured RBAC model. Principle of least privilege throughout.

Multi-Tenant Isolation

PostgreSQL Row-Level Security enforced on every tenant table. Automated security testing validates that Tenant B cannot access Tenant A data.

Immutable Audit Logs

Append-only audit trail. UPDATE and DELETE revoked at the database level. Administrative and security-relevant actions are recorded with actor, timestamp, and context where audit logging is configured.

Signed Recording URLs

Call recordings are never exposed via raw paths. Signed URLs with 1-hour expiry. Expired links return 403, not stale audio.

Backup & Disaster Recovery

Automated database backups with point-in-time recovery. Recording replication to secondary storage. Tested restore procedures.

Infrastructure Monitoring

Real-time alerting on service health, latency budgets, and resource utilization. Grafana SLOs enforce 99.95% uptime per service.

Admin Activity Logging

Administrative and security-relevant actions — user creation, role change, campaign modification, configuration update — are recorded where audit logging is configured.

Compliance

Default-deny. Configured policies enforced before dialing.

Configured outbound dial paths can pass through the compliance engine before dialing. Default-deny can be enforced for configured compliance policies, blocking and logging calls that fail required checks.

DNC/DNCR Enforcement

Supports TDRA (UAE), TCPA (US), CITC (KSA), NTRA (Egypt), and TRC (Jordan) frameworks. Numbers can be checked before dialing when DNC/DNCR enforcement is configured.

Jurisdiction Calling Hours

Calling-hour rules enforced per jurisdiction. UAE default: 9:00-18:00 local, Sunday through Thursday. Fully configurable per campaign.

Consent Proof Chain

Consent records can include proof URL, IP address, user-agent, timestamp, and source. Retention policies are configurable per campaign and jurisdiction.

CLI Ownership Verification

Caller ID numbers verified per tenant per jurisdiction. No tenant can spoof another tenant's CLI. Ownership audited continuously.

Default-Deny on Failure

Configured default-deny policies can block calls when compliance checks fail, rule versions are unknown, or services return errors.

Immutable Decision Trail

Compliance decisions can be recorded with rule version, audit reference, and context where audit logging is configured. Recorded decisions are append-only.

Recording Retention Policies

Per-tenant configurable retention periods. Recordings stored according to jurisdiction requirements. Automatic expiry enforcement.

Compliance Reporting

Real-time dashboards showing block rates, DNC hit rates, consent expiry, and calling-hour violations. Exportable for regulatory audit.

AI & Data Practices

Transparent AI. Your data stays yours.

AI features are optional, off by default, and never use your audio to train shared models. Full human override at every step.

Minimal Audio Processing

AMD classification is designed to process a short initial segment of call audio. Full-call audio analysis is not performed without explicit opt-in. Detailed AI data policy available on request.

No Long-Term Transcript Storage

Transcripts generated for AMD classification are used in real time and are not stored long-term. Classification results are retained; raw transcripts are not.

Per-Tenant Model Training

AMD feedback can be tenant-scoped and governed by customer retention and AI settings. No cross-pollination between tenants by default.

No Shared Model Training

Customer call data is not used to train shared cross-tenant models by default. AMD feedback can be tenant-scoped and governed by customer retention and AI settings.

Off by Default

AI features can be controlled by tenant-level feature flags and opt-in settings. Nothing activates without explicit tenant configuration.

Human Override Always Available

Agents can override any AI classification at any time. AI assists; humans decide. Automated decisions are always reviewable.

Full Opt-Out Available

Tenants can disable all AI features entirely with a single configuration change. The platform operates at full capability without AI.

AI Decision Audit Trail

AI classifications can be logged with confidence score, model version, and human override status where audit logging is configured.

Data Residency & Storage

Know exactly where your data lives

All data is tenant-isolated at every layer. Storage locations and retention policies are configurable per tenant to meet jurisdiction requirements.

Private Cloud Recording Storage

Call recordings are stored in MinIO on private cloud infrastructure. No third-party object storage. Full control over data locality and access policies.

PostgreSQL for Structured Data

All structured data — contacts, campaigns, compliance decisions, audit logs — stored in PostgreSQL 16 with Row-Level Security enforced on every tenant table.

Redis for Ephemeral Data

Session data, real-time agent state, and caching use Redis. Ephemeral by design. No persistent customer data stored in cache layers.

Complete Tenant Isolation

Controls are designed to prevent cross-tenant data access, with row-level security, scoped tokens, and automated security testing.

Configurable Retention

Recording retention, audit log retention, and data lifecycle policies are configurable per tenant. Automatic enforcement of retention windows.

Encrypted at Every Layer

Data encrypted in transit between all services (mTLS). Encrypted at rest in PostgreSQL, MinIO, and backup storage. Key management follows industry best practices.

Compliance disclaimer

DialerBee provides compliance-supporting tools, configurable controls, audit logs, and enforcement workflows designed to help organizations meet regulatory requirements. Customers remain responsible for their own legal compliance and should consult qualified counsel for jurisdiction-specific requirements. Regulatory frameworks referenced (TDRA, TCPA, CITC, NTRA, TRC) are subject to change.

Security posture

Current implementation status of our security program

Encryption (TLS + AES-256)
Implemented
Role-based access control
Implemented
Multi-tenant isolation (RLS)
Implemented
Immutable audit logs
Implemented
Signed recording URLs
Implemented
Backup & restore testing
Implemented
Infrastructure monitoring
Implemented
SOC 2 Type II
Planned
Penetration testing
Available on request

Questions about security or compliance?

Our team is ready to discuss your requirements, share documentation, and walk through our security practices.