1. Home
  2. Security

Updated 2026-09-29

The controls that exist today.

Calls, recordings and lead lists deserve care. This page lists the specific protections in the product right now, and what we do not have yet. No badges we have not earned.

Access

Recordings behind sign-in
Call recordings stream only to a signed-in user with an operator, VA or admin role. There is no public recording link.
Roles
Admin, agent and VA roles limit who can manage users, export leads and change workspace settings.
Sign-in lockout
Six failed sign-ins on an account trigger a five-minute block.
Rate limits
Sign-in, sign-up, token refresh, password reset and inbound carrier webhooks are rate limited per client.

Sessions and tokens

Refresh token rotation
Refresh tokens are stored hashed and rotate on every use. Replaying an old token revokes every session for that user.
Single-use stream tickets
The live dialer event stream uses one-time tickets that expire in about a minute, so no bearer token ever sits in a URL.
Password resets
Reset links are single use and expire.

Webhooks and secrets

Signed carrier webhooks
Every Telnyx call event is checked against Telnyx's ed25519 signature before it is processed.
Signed outbound webhooks
Disposition events you receive carry an HMAC-SHA256 signature over the timestamp and body.
Encrypted credentials
Carrier credentials stored for a workspace are encrypted at rest with AES-256-GCM.

Transport and browser

HTTPS only
Plain HTTP redirects to HTTPS, with TLS 1.2 as the minimum.
HSTS
dialbreeze.com and app.dialbreeze.com send Strict-Transport-Security, so browsers refuse to downgrade.
Content Security Policy
The app restricts scripts, frames and connections to its own origin and cannot be framed by another site.

AI and data processing

Transcription
Runs on our own servers with a self-hosted speech model. If that model is unavailable, a third-party speech provider, Deepgram, transcribes the recording as a fallback.
Summaries
Produced by a language model on our infrastructure. AI processing runs on Pro and Team only.
Recordings
Stored on our servers in the United States. Playback requires a signed-in user.
Retention and deletion
No configurable retention period yet. Email brayden@themilnerteamfl.com and we delete data on request.

Processors

Stripe
Billing and payments.
Amazon SES
Email delivery.
Cloudflare
Network delivery and protection.
Telnyx
Calls, numbers and carrier services, under your own Telnyx account.

Who does what for DNC and calling rules

Who does what for do-not-call and calling rules
AreaWhat DialBreeze doesWhat you must do
Do-not-call requestsKeeps an internal DNC list. Choosing Do not call on a call marks the lead and adds the number to the suppression list, and suppressed numbers are left out of every session.Scrub lists against the National Do Not Call Registry and any state registries that apply before import, and keep your own record of stop requests.
Calling hoursSkips a lead outside quiet hours in the lead's local time, worked out from the US area code. The default window is 8 a.m. to 9 p.m. local. Unknown area codes are skipped, not dialed.Decide the calling window your rules require, including stricter state windows, and ask us to set it. An area code is not proof of where a person is.
Attempt limitsCaps attempts per lead (a session setting, default 15) and calls to one number per day (default 3) and per week (default 7).Choose limits that fit your campaign rules. A cap is a ceiling, not a target.
Skip reasonsRecords why a lead was not dialed: quiet hours, unknown area code, invalid phone, call cap, do not call, or already engaged.Review skips and fix the list or policy. Do not re-import a number to get around a skip.
ConsentDoes not collect, verify or store proof of consent.Obtain and document any consent your campaign requires before a number is imported.
List sourcingImports the CSV you provide. Does not supply or sell leads.Source lists lawfully and confirm each list is eligible to call.
DisclosuresPlays only the voicemail drops and disconnect message you upload.Identify the caller and business, give any required disclosures, and approve every prerecorded message.
RecordingRecords calls when recording is on for your workspace.Give recording notice and get consent where the law requires it, including in all-party-consent states.

These controls help you run your compliance program. They do not make a campaign compliant on their own, and this table is not legal advice.

Not yet

  • No SOC 2, ISO 27001 or HIPAA attestation. We will say so here when that changes.
  • No single sign-on (SAML or OIDC) yet.
  • No customer-configurable data retention period yet. Deletion is on request by email.

Security questions.

See also the privacy policy and the DNC policy.

Where are recordings stored?
On our servers in the United States. DialBreeze copies each recording from Telnyx for playback and after-call processing, and playback requires a signed-in user. Retention is not configurable yet; email support to have recordings deleted.
Does my call audio leave your servers for AI?
Normally no. Transcription runs on a self-hosted speech model on our servers, and summaries come from a language model on our infrastructure. If the local speech model is unavailable, Deepgram, a third-party speech provider, transcribes the recording instead.
Do you have SOC 2?
No. DialBreeze has no third-party security certification today. This page lists the controls that exist in the product, each of which you can ask us about before you buy.
Who can see my leads?
Users in your workspace, according to their role. The privacy policy explains how support access to workspace data is handled.
How do I report a security issue?
Email brayden@themilnerteamfl.com with the details. We read every report and will reply.

Ask us to show you.

Ask us about any control on this page before you buy.

Request setupPricing