AI Call Deck

Security

Operational AI needs ordinary, disciplined controls.

AI Call Deck separates tenant data, validates actions, minimizes stored audio, and keeps third-party credentials out of frontend code.

Tenant isolation

User queries, calls, appointments, business profiles, billing, OAuth, and notifications are scoped to the authenticated tenant.

Protected authentication

Passwords use modern password hashing, sessions use opaque fingerprinted tokens, and production cookies are secure and HTTP-only.

Encrypted credentials

Google OAuth credentials and mobile push subscriptions are encrypted before database storage.

Immutable billing records

Call usage and wallet transactions retain rate and allocation snapshots for reconciliation.

Stripe-hosted payments

Card details are entered directly on Stripe-hosted Checkout or Portal pages. AI Call Deck does not receive or store full card numbers or card security codes.

Audio minimization

Raw call audio is not logged by default. Transcript storage can be controlled independently.

Validated actions

Calendar booking and call transfer use server-side tools instead of relying on generated text alone.

Payment security responsibilities

AI Call Deck uses HTTPS and sends customers to Stripe-hosted payment pages. Stripe handles card entry and payment processing; AI Call Deck protects account access, validates signed payment notifications, and stores billing references rather than full card details. Customers must also protect their account credentials and review authorized users.

Read billing and refund terms

Responsible boundaries

The receptionist must not invent business facts, confirm availability without checking, expose internal tools, or provide medical, legal, financial, or emergency advice. Businesses remain responsible for notices and consent required by their jurisdiction.

Read the complete Privacy Policy