Security & trust · status as of Oct 10, 2026

What we do today, and what is still to come.

DialSavvy is in early access. Here is every security control with its honest status, instead of a wall of badges.

Independent assurance

Audits and outside testing

As of Oct 10, 2026
  • SOC 2 Type IReport or readiness letter, targeted for launchNo report yet
  • SOC 2 Type IIAfter a 6-month observation window from launchNo report yet
  • ISO 27001After SOC 2 Type IINot started
  • External penetration testOne before beta, another before launchNot yet run

Current status, October 2026. DialSavvy has not completed a SOC 2 or ISO audit, and no independent party has tested our controls yet. Each report will be listed here, with its date, once it exists.

01 · Status board

Every control, with its honest status.

One status per control, from the same list we build against. When a status changes, this page changes with it.

Status key

All 25 controls on this page, telecom fraud included. Each has exactly one status.

  • In place4 controls

    Running today in how DialSavvy is built and sold. Not yet tested by an independent party.

  • In development15 controls

    Designed into the platform being built for launch. Not in production yet.

  • Planned before launch4 controls

    Scheduled before general launch. The timeline below shows the order.

  • Planned after launch2 controls

    Comes after launch, once the first reports are in.

The road to launch

Where each control sits between today and wider assurance. The order is set; the dates are not.

TodayBeing builtPlanned
  1. Today · Oct 10, 2026Early access4 controls in place today. 15 more are being built into the platform for launch.In placeIn development
    • Invite-only workspaces (in place)
    • No carrier credentials from you (in place)
    • Secret scanning and static analysis on every change (in place)
    • Prepaid credits: new calls pause at US$0.00 (in place)
    • 15 controls in development
  2. By launchTested and documentedOutside testing, a first audit report and the papers a security review asks for.Planned before launch
    • External penetration tests, before beta and before launch (planned before launch)
    • SOC 2 Type I report or readiness letter (planned before launch)
    • Trust center: subprocessors, DPA with SCCs, questionnaires, status page (planned before launch)
    • US data region (planned before launch)
  3. Launch + 6 monthsObserved over timeA Type II report covers how controls ran across the whole window, not one day.Planned after launch
    • SOC 2 Type II, after the 6-month observation window (planned after launch)
  4. After SOC 2 Type IIWider assuranceBroader certification and an open invitation to outside researchers.Planned after launch
    • ISO 27001 (planned after launch)
    • Bug bounty (planned after launch)
    • Australian data region (date not set) (planned after launch)
Fig. 1 · Security and assurance timeline · Illustrative · order as planned, dates not set yet

Control by control

20 controls in five groups. The five fraud controls are in Telecom fraud.

Platform

4 controls1 in place · 3 in development

  • No carrier credentials from you

    DialSavvy is the carrier. You never connect or hand us a carrier account, so there is none to leak.

    In place
  • Tenant isolation

    Row-level security on calls, recordings, leads and the ledger. A cross-workspace test on every API route blocks a release.

    In development
  • Encryption and secrets

    Per-workspace keys encrypt your CRM tokens and our carrier credentials. No secrets in URLs, logs or CRM records.

    In development
  • Carrier isolation

    Every workspace gets its own carrier subaccount, managed by DialSavvy. Every carrier callback is signature-checked.

    In development

Identity and access

4 controls1 in place · 3 in development

  • Invite-only workspaces

    Our staff create every workspace and send the owner's invite. There is no self-serve sign-up.

    In place
  • Sign-in

    Google or Microsoft with a verified email, MFA for password sign-ins, and SAML or OIDC single sign-on.

    In development
  • Roles

    Owner, admin, manager and rep, plus a billing admin and a read-only auditor.

    In development
  • SCIM provisioning

    Removing someone frees their seat and ends their live sessions. Enterprise plan.

    In development

Data and AI

4 controls3 in development · 1 before launch

  • Not used for training by default

    Your audio and transcripts don't train models unless your workspace opts in. Enforced in contracts and in storage.

    In development
  • PII redaction

    Transcripts are redacted before they are stored and before any language-model call.

    In development
  • Audit trail

    A hash-chained, append-only log, exported nightly to write-once storage and kept for 5 years.

    In development
  • Data residency

    A US region at launch. An Australian region is planned; choosing a region is an Enterprise option.

    Planned before launch

Build and delivery

3 controls1 in place · 2 in development

  • Secret scanning and static analysis

    Every change to our code is scanned for leaked keys and checked by static analysis and tests before it merges.

    In place
  • Supply chain

    Dependency and container scanning, a software bill of materials and signed images for every release.

    In development
  • Control monitoring

    A compliance-automation platform monitors our controls continuously, from the first weeks of the build.

    In development

Audits and reports

5 controls3 before launch · 2 after launch

  • External penetration tests

    One before beta and another before launch, each by an outside firm.

    Planned before launch
  • SOC 2 Type I

    A Type I report, or a readiness letter, targeted for launch.

    Planned before launch
  • Trust center

    Subprocessor list, DPA with SCCs, pre-filled CAIQ Lite and SIG Lite questionnaires, and a status page.

    Planned before launch
  • SOC 2 Type II

    After a 6-month observation window that starts at launch.

    Planned after launch
  • ISO 27001 and bug bounty

    After SOC 2 Type II.

    Planned after launch

In place means running today, not independently tested. Statuses come from the same list we build against; when one changes, this page changes with it.

02 · Telecom fraud

We're your carrier, so we guard the line.

Toll fraud and runaway spend cost you and us. These limits stand between a stolen login, or a bad list, and your credits.

In development4 of the 5 fraud controls, for launch. Prepaid credits are in place.

Calling guardrailsConceptOwner and admins · Acme
  • Business verificationBefore credits, and again before parallel or international dialingVerified
  • Countries you callEverywhere else stays off until an admin turns it onUSAUGBSGNZ
  • Premium-rate and high-risk prefixesBlocked for every workspace, on every planAlways blocked
  • Destinations above US$0.15 a minuteAn owner or admin opts in firstOff
  • Unusual spendA sudden spike pauses calling until the owner checks itOn
  • Prepaid creditsAt US$0.00 calling pauses. No open tab.US$142.50
Fig. 2 · Calling guardrails in Settings · Concept · fictional data
  • Business verification

    We verify the business before any credits, and again before parallel or international dialing.

    Status: in development.
  • Countries you choose

    Calls go only to countries your admin turns on. High-risk and premium-rate prefixes are always blocked.

    Status: in development.
  • Opt-in for costly destinations

    An owner or admin opts in before anyone can call a destination above US$0.15 a minute.

    Status: in development.
  • Spend limits

    Limits on how fast credits are spent. An unusual spike pauses calling automatically.

    Status: in development.
  • Prepaid credits

    Calls, numbers and AI draw from prepaid credits, and every call is itemized. At US$0.00 new calls pause and a call in progress finishes, so there is no open tab.

    Status: in place.

03 · Your data

What we keep, and for how long.

Default retention as designed for launch.

  • SubprocessorsThe companies that help run DialSavvy, for hosting, telephony, speech, AI, identity and payments, are listed before launch.Planned before launch
  • Not for saleWe do not sell personal data. Our privacy notice covers this website and the demo form.Read the privacy notice
  • Recording rules by countryRecording is on today. Notice and consent rules per country and US state are coming.ComingHow compliance works

Default retention

Per workspace, as designed for launch

In development
Default retention per workspace, as designed for launch
DataKept forScale in years
Call recordsEach attempt, its compliance checks and its outcome5 years
RecordingsWhen recording is on for the call12 monthsUp to 60 months at extra cost
Transcripts and AI notesRedacted before they are storedSame as the recording
Billing ledgerCredits, charges and invoices7 years
Compliance audit logHash-chained and write-once5 years

04 · Report an issue

Found a problem? Tell us privately.

Please don't open a public issue or post details where others can see them. If you're reviewing us for your team, the papers are here too.

Report a security issue

Email, with “Security” in the subjecthello@dialsavvy.comAlso in our security.txt.

Please include

  1. 01The affected page, endpoint or component, and how to reproduce it
  2. 02The impact you expect, and whether real credentials or customer data are involved
  3. 03Where a leaked secret is, never the secret itself

Our response targets

  • Acknowledge your report2 business days
  • Triage and set severity5 business days
  • Fix a critical issue7 days
  • Fix a high issue30 days

These are targets from our security policy, not promises.

Reviewing DialSavvy for your team?

The papers a security review asks for, each with its current status.

Rather walk through it live?Book a demo

Ask us the hard questions.

Early access is by invitation. We set up your workspace, numbers and caller ID, then send your invite.