Security

Last updated: 11 September 2026 · Honest controls — no fake certification badges

KwikCall is built for production voice workloads. Below is what we operate today, what we are hardening, and how to reach us for incidents.

Trust matrix

AreaControlStatus
TransportHTTPS, TLS 1.2+, HSTS, security headers on public hostsLive
Authbcrypt passwords, JWT access/refresh, login rate limits, role checksLive
Tenant isolationOrg-scoped APIs for agents, contacts, calls, billingLive
SecretsIntegration secrets Fernet-encrypted at rest; `.env` mode 600 on app hostLive
Admin surfaceSuperadmin routes require elevated auth; OpenAPI disabled in productionLive
BackupsNightly DB dump + deploy-time file backups before major changesLive
Data residencyPrimary production currently Azure India (Central India VM)Documented
PaymentsStripe processor; no full card PAN stored by KwikCallScaffolded / gated
SSO / SOC2 packEnterprise paperwork & IdP SSORoadmap

Data residency

Application, Postgres, and Redis for the live stack run on our Azure India VM. Cloudflare terminates edge TLS. Recordings and transcripts stay in the tenant’s workspace subject to retention settings.

Incident response

We do not display invented ISO/SOC badges. When third-party audits complete, we will publish the report summaries here.

Related: Privacy · Terms · Docs