- Home
- Security
Updated 2026-09-29
The controls that exist today.
Calls, recordings and lead lists deserve care. This page lists the specific protections in the product right now, and what we do not have yet. No badges we have not earned.
Access
- Recordings behind sign-in
- Call recordings stream only to a signed-in user with an operator, VA or admin role. There is no public recording link.
- Roles
- Admin, agent and VA roles limit who can manage users, export leads and change workspace settings.
- Sign-in lockout
- Six failed sign-ins on an account trigger a five-minute block.
- Rate limits
- Sign-in, sign-up, token refresh, password reset and inbound carrier webhooks are rate limited per client.
Sessions and tokens
- Refresh token rotation
- Refresh tokens are stored hashed and rotate on every use. Replaying an old token revokes every session for that user.
- Single-use stream tickets
- The live dialer event stream uses one-time tickets that expire in about a minute, so no bearer token ever sits in a URL.
- Password resets
- Reset links are single use and expire.
Webhooks and secrets
- Signed carrier webhooks
- Every Telnyx call event is checked against Telnyx's ed25519 signature before it is processed.
- Signed outbound webhooks
- Disposition events you receive carry an HMAC-SHA256 signature over the timestamp and body.
- Encrypted credentials
- Carrier credentials stored for a workspace are encrypted at rest with AES-256-GCM.
Transport and browser
- HTTPS only
- Plain HTTP redirects to HTTPS, with TLS 1.2 as the minimum.
- HSTS
- dialbreeze.com and app.dialbreeze.com send Strict-Transport-Security, so browsers refuse to downgrade.
- Content Security Policy
- The app restricts scripts, frames and connections to its own origin and cannot be framed by another site.
AI and data processing
- Transcription
- Runs on our own servers with a self-hosted speech model. If that model is unavailable, a third-party speech provider, Deepgram, transcribes the recording as a fallback.
- Summaries
- Produced by a language model on our infrastructure. AI processing runs on Pro and Team only.
- Recordings
- Stored on our servers in the United States. Playback requires a signed-in user.
- Retention and deletion
- No configurable retention period yet. Email brayden@themilnerteamfl.com and we delete data on request.
Processors
- Stripe
- Billing and payments.
- Amazon SES
- Email delivery.
- Cloudflare
- Network delivery and protection.
- Telnyx
- Calls, numbers and carrier services, under your own Telnyx account.
Recording consent
You are responsible for giving any notice and getting any consent that recording a call requires under federal and state law. Some states require every party to consent, so check the rules for the states you call into, not only your own.
Recording is enabled at the workspace level by our team, not switched per call. Ask us to turn it on or off for your workspace. When it is off, there is no recording for the after-call AI to process.
Who does what for DNC and calling rules
| Area | What DialBreeze does | What you must do |
|---|---|---|
| Do-not-call requests | Keeps an internal DNC list. Choosing Do not call on a call marks the lead and adds the number to the suppression list, and suppressed numbers are left out of every session. | Scrub lists against the National Do Not Call Registry and any state registries that apply before import, and keep your own record of stop requests. |
| Calling hours | Skips a lead outside quiet hours in the lead's local time, worked out from the US area code. The default window is 8 a.m. to 9 p.m. local. Unknown area codes are skipped, not dialed. | Decide the calling window your rules require, including stricter state windows, and ask us to set it. An area code is not proof of where a person is. |
| Attempt limits | Caps attempts per lead (a session setting, default 15) and calls to one number per day (default 3) and per week (default 7). | Choose limits that fit your campaign rules. A cap is a ceiling, not a target. |
| Skip reasons | Records why a lead was not dialed: quiet hours, unknown area code, invalid phone, call cap, do not call, or already engaged. | Review skips and fix the list or policy. Do not re-import a number to get around a skip. |
| Consent | Does not collect, verify or store proof of consent. | Obtain and document any consent your campaign requires before a number is imported. |
| List sourcing | Imports the CSV you provide. Does not supply or sell leads. | Source lists lawfully and confirm each list is eligible to call. |
| Disclosures | Plays only the voicemail drops and disconnect message you upload. | Identify the caller and business, give any required disclosures, and approve every prerecorded message. |
| Recording | Records calls when recording is on for your workspace. | Give recording notice and get consent where the law requires it, including in all-party-consent states. |
These controls help you run your compliance program. They do not make a campaign compliant on their own, and this table is not legal advice.
Not yet
- No SOC 2, ISO 27001 or HIPAA attestation. We will say so here when that changes.
- No single sign-on (SAML or OIDC) yet.
- No customer-configurable data retention period yet. Deletion is on request by email.
Security questions.
See also the privacy policy and the DNC policy.
Where are recordings stored?
Does my call audio leave your servers for AI?
Do you have SOC 2?
Who can see my leads?
How do I report a security issue?
Ask us to show you.
Ask us about any control on this page before you buy.