TRUST & SECURITY

Clear boundaries are part of the product.

EnableCalls is designed so customer data, provider secrets, live audio, billing and private media each stay inside an explicit responsibility boundary.

Built for IndiaHuman review stays in controlExplicit system state
Tenant boundaryaccount_id scoped
Web app
Control plane
Realtime
Private media
SECURITY BY ARCHITECTURE

Four boundaries. No hidden shortcut.

The marketing site describes the current architecture without claiming certifications that have not been established.

Customer web app

Uses customer sessions and never receives service-role or provider secrets.

FastAPI control plane

Owns tenant data, configuration, billing, authorisation and engine assignment.

Realtime engine

Owns live audio only, with one cancellable async pipeline per call.

Private storage

Final recordings and media target Cloudflare R2 with signed access.

PLATFORM CONTROLS

Designed for accountable operation.

Security is not a single badge. It is how the product scopes data, validates authority, handles secrets and records sensitive state changes.

ControlEnforcement pointState
Tenant-scoped data

Customer-owned rows carry account scope, with RLS and backend authorisation preventing cross-tenant access.

Designed boundary
Server-side secrets

Supabase service role, telephony credentials and payment secrets never belong in the browser.

Designed boundary
Private call media

Recordings and private media target Cloudflare R2 with signed access boundaries.

Designed boundary
Explicit admin access

Administrative capabilities use an explicit entitlement, not an implied customer role.

Designed boundary
Truthful provider state

Unverified contracts and unavailable credentials surface as unconfigured instead of silently falling back to fake success.

Designed boundary
Append-only billing ledger

Wallet mutations are transaction-safe, idempotent and recorded as an auditable ledger.

Designed boundary
HONEST LIMITS

Security claims should be as explicit as the controls.

This page intentionally does not claim SOC 2, ISO 27001, HIPAA or another certification that is not evidenced in the project documentation. Deployment-specific compliance, retention and data-processing commitments require formal review.

Current platform principles

  • Tenant scope on customer-owned data
  • RLS plus backend authorisation
  • Private recording storage
  • Explicit admin entitlement
  • No browser-exposed secrets
  • Provider operations fail closed
READY WHEN YOU ARE

Have a security or deployment question?

Bring the data flow, retention requirement or integration boundary you need reviewed.

Book a demo Test it before it goes live Pay only for connected calls