Security & Trust
InfraVoice is built for production voice workloads with sensitive customer conversations. Security controls are applied per workspace and enforced at every service boundary.
Data & secrets
- Encryption at rest — provider API keys, tool auth headers, and credentials are encrypted; they are never returned in plaintext or exposed to the model.
- Encryption in transit — all traffic (dashboard, REST, WebSocket, telephony) is TLS.
- Workspace isolation — agents, knowledge, calls, and recordings are scoped to a workspace; cross-workspace access is blocked at the data layer.
Access & auth
- Token-based API access with per-workspace scoping.
- Role-based access in the dashboard and the human-agent portal.
- Internal service calls are authenticated between services and never exposed publicly.
Recordings & transcripts
Call recordings, transcripts, and summaries are scoped to your workspace. Retention is set at the platform level, not per workspace: per-turn call audio is deleted after 30 days (a fixed platform setting, enforced by an object-storage lifecycle rule applied per environment). Full call recordings and transcripts are retained for the life of the workspace — they have no automatic expiry. There is currently no self-service retention control; if you need a different window, contact us. You control whether a call is recorded and can disable capture per agent.