AI Call Deck

Security

Operational AI needs ordinary, disciplined controls.

AI Call Deck separates tenant data, validates actions, minimizes stored audio, and keeps third-party credentials out of frontend code.

Tenant isolation

User queries, calls, appointments, business profiles, billing, OAuth, and notifications are scoped to the authenticated tenant.

Protected authentication

Passwords use modern password hashing, sessions use opaque fingerprinted tokens, and production cookies are secure and HTTP-only.

Encrypted credentials

Google OAuth credentials and mobile push subscriptions are encrypted before database storage.

Immutable billing records

Call usage and wallet transactions retain rate and allocation snapshots for reconciliation.

Audio minimization

Raw call audio is not logged by default. Transcript storage can be controlled independently.

Validated actions

Calendar booking and call transfer use server-side tools instead of relying on generated text alone.

Responsible boundaries

The receptionist must not invent business facts, confirm availability without checking, expose internal tools, or provide medical, legal, financial, or emergency advice. Businesses remain responsible for notices and consent required by their jurisdiction.

Read the complete Privacy Policy