Security and privacy

Boundaries first, evidence always.

Frontal Voice is designed with tenant isolation, least privilege, verified events, controlled retention, and honest disclosure.

Tenant isolation

Every tenant query is scoped in API and service layers, with automated cross-tenant read and write tests.

Audited actions

Sensitive changes, publishing, impersonation, billing operations, and event replays create audit records.

Secure call data

Recording access is signed or proxied; permanent provider recording URLs are not exposed directly.

Verified webhooks

Signatures, timestamps, replay protection, idempotency, retries, dead letters, and manual replay protect provider events.

Retention controls

Plan-aware retention and controlled deletion workflows limit how long call data remains available.

Clear claims

Frontal Voice does not claim regulatory certification. Tenants remain responsible for jurisdiction-specific disclosure and consent decisions.