Security measures covering encryption in transit, access management, organization data isolation, integrations, privacy rights, and software delivery.
Security and data protection
Encryption in transit
Telagento uses HTTPS/TLS for customer-facing traffic and managed-provider API connections. This protects the confidentiality and integrity of data while it moves between a user's browser, Telagento, and selected service providers.
Identity and access management
Dashboard and administrative routes require authentication and apply role-based authorization. Access is limited to the functions assigned to each user. Runtime secrets are stored outside source code.
Organization data isolation
Every Telagento user and data request is evaluated within an organization context. Organization-scoped authorization and database queries apply that context to workspace and record access. Row-level controls add defense in depth on covered tables. Authorized Telagento administrators may access an organization when required to assist the customer.
Application and integration security
Covered Twilio voice and ElevenLabs conversational and post-call callbacks use signature verification so Telagento can check who sent them. Telagento-managed webhook clients covered by this control require HTTPS, reject private network destinations and redirects, pin approved DNS results, and limit response size and duration.
Data lifecycle management and privacy rights
Administrative erasure covers covered conversation, call, transcript, and widget records in active Telagento-operated systems. Configurable retention applies to covered call and transcript data. Covered call records can be exported administratively, and covered conversation transcripts can be exported per conversation. The privacy section below explains what these actions cover and where provider, backup, or connected-system boundaries apply.
Secure software development and vulnerability response
Telagento uses branch-based code review, automated tests, controlled promotion from development through release environments, operational logging, and private vulnerability reporting. These practices reduce release risk and provide a defined path to investigate security concerns.
Privacy
GDPR and CCPA data rights
For verified GDPR or CCPA requests, Telagento works with the customer that controls the data to export or delete covered records held in Telagento-operated systems.
GDPR access and deletion
For a verified GDPR request, Telagento can export covered call records and individual conversation transcripts, and can delete covered conversation, call, transcript, and widget records from active Telagento-operated systems. Telagento coordinates fulfillment with the customer responsible for the data.
CCPA access and deletion
For a verified California consumer request, Telagento can export covered call records and individual conversation transcripts, and can delete covered conversation, call, transcript, and widget records from active Telagento-operated systems. Telagento coordinates fulfillment with the customer responsible for the data.
Scope boundaries
Requests about customer-directed conversation data are coordinated with the customer responsible for that data. Telagento can export covered call records and individual conversation transcripts, and can delete covered conversation, call, transcript, and widget records from active Telagento-operated systems. Deleting Telagento-operated records does not independently delete copies retained by enabled service providers. Derived analytics and aggregate records remain subject to applicable retention and customer terms. Legal retention requirements and normal backup-expiration schedules may delay final removal from every copy. Data written to a customer's connected systems remains under that customer's control, and provider-held copies follow the applicable provider procedure and contract.