1 Our approach
Security is built into how the Service is designed and operated. We follow the principle of least privilege, isolate customers from one another, and keep audit trails of sensitive actions. The summary below reflects current practice; specific controls evolve as we grow.
Encryption in transit
Traffic to the dashboard and API is served over HTTPS/TLS. Telephony media is carried over the provider's secured channels.
Tenant isolation
Each customer is a separate tenant with its own configuration, contacts, and call data, segregated at the application layer.
Access control
Administrative access is restricted to authorised staff on a need-to-know basis and protected by strong authentication.
Audit logging
Sensitive actions and billing events are logged to support investigation and accountability.
Data location
Customer data, recordings, and transcripts are stored on infrastructure in India (Bengaluru region).
Secrets handling
API keys and credentials are stored separately from code and rotated when needed.
Agent guardrails
The rules every call follows — it says it is automated, it stops when asked, it never asks for an OTP — are applied server-side around every prompt at render time. No account setting or instruction can remove them.
Call reach limits
An agent can only dial numbers the account has verified; calling beyond them requires an approved Business account. Every plan also has a maximum call length and a daily dial cap, so a misconfigured agent stays contained.
2 Data handling
Every call through Aunbound is recorded and transcribed, including calls placed by an individual's own agent. We store recordings and transcripts to show you what happened on a call, classify its outcome, support billing, and resolve disputes. Access is limited to the account that owns the call and to authorised staff. Recordings and transcripts are retained for 12 months and then deleted, unless law requires otherwise or they are subject to an open dispute; you can ask us to delete a recording sooner. Payment card data is handled by our payment processor, Razorpay, and never reaches our systems. For the full picture, including the third-party providers involved in a call, see our Privacy Policy.
Note: while data is stored in India, some real-time processing (speech recognition, language-model inference, lead research) is performed by sub-processors that may operate outside India. We disclose this in our Privacy Policy rather than claim full data localisation.
3 Infrastructure
The Service runs on reputable cloud and telephony providers. We apply security updates to our systems, separate production from development where practical, and design for tenant isolation across a shared, capacity-managed worker pool. We rely on our providers' physical and network security at the infrastructure layer.
4 Shared responsibility
Security is shared. We secure the platform; you secure your use of it:
- Keep account credentials confidential and use strong, unique passwords.
- Limit and review who has access to your account.
- Only verify or upload numbers you are permitted to call, and honour opt-outs.
- Review the agents on your account and pause or delete any you no longer want calling.
- Tell us immediately if you suspect unauthorised access — an attacker with your account could schedule calls from your number.
5 Reliability and backups
We take operational measures to keep the Service available and to back up critical data. No service can guarantee zero downtime or data loss; our commitments on availability are set out in the Terms of Service.
6 Reporting a vulnerability
Found a security issue?
We welcome reports from researchers and users. Please email dhipinkumar@gmail.com with details and steps to reproduce. We ask that you give us a reasonable opportunity to investigate and fix the issue before any public disclosure, and that you avoid accessing or modifying other people's data during testing.
We will acknowledge valid reports and keep you informed of our progress. We do not currently operate a paid bounty programme, but we are glad to credit researchers who report responsibly. Please do not place test calls to numbers you do not own, or run load tests against the dialler.
7 Incident response
If we become aware of a security incident affecting personal data, we will investigate, take steps to contain and remediate it, and notify affected customers and authorities where required by law, within applicable timeframes.
8 Contact
- Security: dhipinkumar@gmail.com
- General: dhipinkumar@gmail.com