What we do today, and what is still to come.
DialSavvy is in early access. Here is every security control with its honest status, instead of a wall of badges.
Independent assurance
Audits and outside testing
- SOC 2 Type IReport or readiness letter, targeted for launchNo report yet
- SOC 2 Type IIAfter a 6-month observation window from launchNo report yet
- ISO 27001After SOC 2 Type IINot started
- External penetration testOne before beta, another before launchNot yet run
Current status, October 2026. DialSavvy has not completed a SOC 2 or ISO audit, and no independent party has tested our controls yet. Each report will be listed here, with its date, once it exists.
01 · Status board
Every control, with its honest status.
One status per control, from the same list we build against. When a status changes, this page changes with it.
Status key
All 25 controls on this page, telecom fraud included. Each has exactly one status.
- In place4 controls
Running today in how DialSavvy is built and sold. Not yet tested by an independent party.
- In development15 controls
Designed into the platform being built for launch. Not in production yet.
- Planned before launch4 controls
Scheduled before general launch. The timeline below shows the order.
- Planned after launch2 controls
Comes after launch, once the first reports are in.
The road to launch
Where each control sits between today and wider assurance. The order is set; the dates are not.
- Today · Oct 10, 2026Early access4 controls in place today. 15 more are being built into the platform for launch.In placeIn development
- Invite-only workspaces (in place)
- No carrier credentials from you (in place)
- Secret scanning and static analysis on every change (in place)
- Prepaid credits: new calls pause at US$0.00 (in place)
- 15 controls in development
- By launchTested and documentedOutside testing, a first audit report and the papers a security review asks for.Planned before launch
- External penetration tests, before beta and before launch (planned before launch)
- SOC 2 Type I report or readiness letter (planned before launch)
- Trust center: subprocessors, DPA with SCCs, questionnaires, status page (planned before launch)
- US data region (planned before launch)
- Launch + 6 monthsObserved over timeA Type II report covers how controls ran across the whole window, not one day.Planned after launch
- SOC 2 Type II, after the 6-month observation window (planned after launch)
- After SOC 2 Type IIWider assuranceBroader certification and an open invitation to outside researchers.Planned after launch
- ISO 27001 (planned after launch)
- Bug bounty (planned after launch)
- Australian data region (date not set) (planned after launch)
Control by control
20 controls in five groups. The five fraud controls are in Telecom fraud.
Platform
4 controls1 in place · 3 in development
No carrier credentials from you
DialSavvy is the carrier. You never connect or hand us a carrier account, so there is none to leak.
In placeTenant isolation
Row-level security on calls, recordings, leads and the ledger. A cross-workspace test on every API route blocks a release.
In developmentEncryption and secrets
Per-workspace keys encrypt your CRM tokens and our carrier credentials. No secrets in URLs, logs or CRM records.
In developmentCarrier isolation
Every workspace gets its own carrier subaccount, managed by DialSavvy. Every carrier callback is signature-checked.
In development
Identity and access
4 controls1 in place · 3 in development
Invite-only workspaces
Our staff create every workspace and send the owner's invite. There is no self-serve sign-up.
In placeSign-in
Google or Microsoft with a verified email, MFA for password sign-ins, and SAML or OIDC single sign-on.
In developmentRoles
Owner, admin, manager and rep, plus a billing admin and a read-only auditor.
In developmentSCIM provisioning
Removing someone frees their seat and ends their live sessions. Enterprise plan.
In development
Data and AI
4 controls3 in development · 1 before launch
Not used for training by default
Your audio and transcripts don't train models unless your workspace opts in. Enforced in contracts and in storage.
In developmentPII redaction
Transcripts are redacted before they are stored and before any language-model call.
In developmentAudit trail
A hash-chained, append-only log, exported nightly to write-once storage and kept for 5 years.
In developmentData residency
A US region at launch. An Australian region is planned; choosing a region is an Enterprise option.
Planned before launch
Build and delivery
3 controls1 in place · 2 in development
Secret scanning and static analysis
Every change to our code is scanned for leaked keys and checked by static analysis and tests before it merges.
In placeSupply chain
Dependency and container scanning, a software bill of materials and signed images for every release.
In developmentControl monitoring
A compliance-automation platform monitors our controls continuously, from the first weeks of the build.
In development
Audits and reports
5 controls3 before launch · 2 after launch
External penetration tests
One before beta and another before launch, each by an outside firm.
Planned before launchSOC 2 Type I
A Type I report, or a readiness letter, targeted for launch.
Planned before launchTrust center
Subprocessor list, DPA with SCCs, pre-filled CAIQ Lite and SIG Lite questionnaires, and a status page.
Planned before launchSOC 2 Type II
After a 6-month observation window that starts at launch.
Planned after launchISO 27001 and bug bounty
After SOC 2 Type II.
Planned after launch
In place means running today, not independently tested. Statuses come from the same list we build against; when one changes, this page changes with it.
02 · Telecom fraud
We're your carrier, so we guard the line.
Toll fraud and runaway spend cost you and us. These limits stand between a stolen login, or a bad list, and your credits.
In development4 of the 5 fraud controls, for launch. Prepaid credits are in place.
- Business verificationBefore credits, and again before parallel or international dialingVerified
- Countries you callEverywhere else stays off until an admin turns it onUSAUGBSGNZ
- Premium-rate and high-risk prefixesBlocked for every workspace, on every planAlways blocked
- Destinations above US$0.15 a minuteAn owner or admin opts in firstOff
- Unusual spendA sudden spike pauses calling until the owner checks itOn
- Prepaid creditsAt US$0.00 calling pauses. No open tab.US$142.50
Business verification
We verify the business before any credits, and again before parallel or international dialing.
Status: in development.Countries you choose
Calls go only to countries your admin turns on. High-risk and premium-rate prefixes are always blocked.
Status: in development.Opt-in for costly destinations
An owner or admin opts in before anyone can call a destination above US$0.15 a minute.
Status: in development.Spend limits
Limits on how fast credits are spent. An unusual spike pauses calling automatically.
Status: in development.Prepaid credits
Calls, numbers and AI draw from prepaid credits, and every call is itemized. At US$0.00 new calls pause and a call in progress finishes, so there is no open tab.
Status: in place.
03 · Your data
What we keep, and for how long.
Default retention as designed for launch.
- SubprocessorsThe companies that help run DialSavvy, for hosting, telephony, speech, AI, identity and payments, are listed before launch.Planned before launch
- Not for saleWe do not sell personal data. Our privacy notice covers this website and the demo form.Read the privacy notice
- Recording rules by countryRecording is on today. Notice and consent rules per country and US state are coming.ComingHow compliance works
Default retention
Per workspace, as designed for launch
| Data | Kept for | Scale in years |
|---|---|---|
| Call recordsEach attempt, its compliance checks and its outcome | 5 years | |
| RecordingsWhen recording is on for the call | 12 monthsUp to 60 months at extra cost | |
| Transcripts and AI notesRedacted before they are stored | Same as the recording | |
| Billing ledgerCredits, charges and invoices | 7 years | |
| Compliance audit logHash-chained and write-once | 5 years |
04 · Report an issue
Found a problem? Tell us privately.
Please don't open a public issue or post details where others can see them. If you're reviewing us for your team, the papers are here too.
Report a security issue
Please include
- 01The affected page, endpoint or component, and how to reproduce it
- 02The impact you expect, and whether real credentials or customer data are involved
- 03Where a leaked secret is, never the secret itself
Our response targets
- Acknowledge your report2 business days
- Triage and set severity5 business days
- Fix a critical issue7 days
- Fix a high issue30 days
These are targets from our security policy, not promises.
Reviewing DialSavvy for your team?
The papers a security review asks for, each with its current status.
- The website and the demo form.
- Every call checked before it rings.
- Calling modes by country, with an as-of date.
- Every Early access and Coming status in one list.
- Security questionnairesPre-filled CAIQ Lite and SIG LitePlanned before launch