Callvend
Loading 00%

Call data is the sensitive kind

How CallVend protects call data: encryption, data residency, access control, retention and the reports your security team will ask for.

Encrypted in transit

Signalling and media travel over encrypted transport. Recordings are held in object storage rather than on the application servers.

Data residency

A workspace is created in one region — US or EU — and that choice is permanent. Call data stays in the region it was created in.

Identity and access

SAML single sign-on, custom roles defined per workspace, role-based permissions, and two-factor authentication that can be enforced org-wide.

Append-only audit trail

Privileged actions are recorded with actor and timestamp on a trail that is written to and never edited, including access by our own support staff.

Retention and erasure

Retention windows for recordings and transcripts are set per workspace, within platform bounds. Customers can request export or erasure of their data.

Verified accounts, monitored calling

The account holder is identity-checked at signup, including a liveness check. Calling patterns are reviewed automatically and suspected abuse can be held.

For your review

What we can send you

  • Architecture overview covering the media path, storage and backups
  • Current sub-processor list with the region each operates in
  • Data processing agreement, on request
  • A completed copy of your own security questionnaire

Reporting a vulnerability

Email us with the details and a way to reproduce it. We acknowledge within one working day, keep you updated while we fix it, and credit you if you would like us to. We will not pursue legal action against good-faith research that stays within your own account.

Incidents

We contact affected customers directly when there is an incident touching their account, including the cause and what changed afterwards. For incidents affecting personal data we notify without undue delay and within the timeframes our data processing agreement commits to. We do not yet run a public status page — that is on the roadmap, and until it exists we will not pretend otherwise.

support@greyexpeditelogistics.com
Security FAQ

What a review usually asks first

The people your roles allow, and nobody else by default. Built-in roles cover the usual shapes and custom roles cover the rest; access by CallVend’s own support staff is a privileged action and is written to the same append-only audit trail as everything else.

Yes — US or EU, chosen when the workspace is created. The choice is permanent, because changing it would mean migrating stored recordings and transcripts rather than flipping a setting.

With a password plus two-factor authentication using a TOTP authenticator app, backed by single-use recovery codes. SAML 2.0 single sign-on against your own identity provider is available on every plan.

The account holder is identity-checked at signup, including document and liveness checks. Calling patterns are then reviewed automatically, and suspected abuse can be held while it is looked at rather than discovered in a monthly report.

Call records, contacts and transcripts export, and erasure is a documented operation you can ask for. Retention windows mean recordings and transcripts can be set to delete themselves long before that point.

Bring it to your security team.

We will complete the questionnaire and get on a call with them if it helps.