Security program
SIPforge is designed around enterprise security practices: least-privilege access, organization-scoped data, encrypted transport, sensitive-secret handling, audit-friendly workflows, and operational monitoring. Security is a shared responsibility between SIPforge, workspace administrators, users, and connected providers.
Access control
- Role-based access separates viewers, runners, and organization administrators.
- Authenticated sessions use short-lived access tokens and refresh handling.
- Administrative pages such as provider keys, agents, and settings are restricted to organization admins.
- Users should protect credentials, avoid shared accounts, and remove access promptly when staff leave or roles change.
Encryption and secret protection
- Production deployments should enforce HTTPS/TLS for browser, API, webhook, and provider traffic.
- Provider credentials, API keys, and SIP secrets should be encrypted or stored in managed secret stores where supported.
- Secrets should not be placed in screenshots, test names, prompts, media filenames, or support tickets unless explicitly required and protected.
- Credential rotation should be performed after staff changes, suspected exposure, or provider policy updates.
Data isolation and auditability
Workspace data should be scoped by organization. Test results, reports, transcripts, provider events, and configuration records should be available only to authorized users in the relevant workspace. Audit-friendly records help administrators investigate changes, failures, provider errors, and access patterns.
Telephony and AI provider security
Connected Twilio, SIP, STT, TTS, and LLM providers process data according to their own terms and security programs. Customers should choose providers that meet their compliance needs, configure callback URLs carefully, restrict provider account access, and avoid sending regulated data unless authorized.
Operational safeguards
- Cost caps and conservative limits reduce blast radius for billable voice and AI tests.
- Live status, failures, alerts, and logs help detect misconfiguration and provider issues quickly.
- Exports should be shared only with authorized recipients because they may contain phone numbers, transcripts, errors, and infrastructure details.
- Backups, retention, and deletion should follow the customer's contractual and regulatory obligations.
Incident response
Suspected unauthorized access, credential exposure, data leakage, or provider compromise should be escalated immediately to the organization administrator and the SIPforge support/security contact. Administrators should rotate affected secrets, review access, pause risky schedules, and preserve relevant logs.
No absolute guarantee
No internet-connected service can guarantee perfect security. SIPforge aims to reduce risk with layered controls, clear ownership, and operational visibility, while customers remain responsible for secure configuration and lawful use of their connected systems.
Questions about this policy can go to your organization administrator or to hello@sipforge.com. You can also contact SIPforge.
