AUNbound

Trust

Security

Aunbound places real phone calls and holds the recordings of them, for individuals and for businesses. This page describes the measures we take to protect that data, the safety rules that hold on every call, and how to report a problem.

Last updated: 10 October 2026

1 Our approach

Security is built into how the Service is designed and operated. We follow the principle of least privilege, isolate customers from one another, and keep audit trails of sensitive actions. The summary below reflects current practice; specific controls evolve as we grow.

Encryption in transit

Traffic to the dashboard and API is served over HTTPS/TLS. Telephony media is carried over the provider's secured channels.

Tenant isolation

Each customer is a separate tenant with its own configuration, contacts, and call data, segregated at the application layer.

Access control

Administrative access is restricted to authorised staff on a need-to-know basis and protected by strong authentication.

Audit logging

Sensitive actions and billing events are logged to support investigation and accountability.

Data location

Customer data, recordings, and transcripts are stored on infrastructure in India (Bengaluru region).

Secrets handling

API keys and credentials are stored separately from code and rotated when needed.

Agent guardrails

The rules every call follows — it says it is automated, it stops when asked, it never asks for an OTP — are applied server-side around every prompt at render time. No account setting or instruction can remove them.

Call reach limits

An agent can only dial numbers the account has verified; calling beyond them requires an approved Business account. Every plan also has a maximum call length and a daily dial cap, so a misconfigured agent stays contained.

2 Data handling

Every call through Aunbound is recorded and transcribed, including calls placed by an individual's own agent. We store recordings and transcripts to show you what happened on a call, classify its outcome, support billing, and resolve disputes. Access is limited to the account that owns the call and to authorised staff. Recordings and transcripts are retained for 12 months and then deleted, unless law requires otherwise or they are subject to an open dispute; you can ask us to delete a recording sooner. Payment card data is handled by our payment processor, Razorpay, and never reaches our systems. For the full picture, including the third-party providers involved in a call, see our Privacy Policy.

Note: while data is stored in India, some real-time processing (speech recognition, language-model inference, lead research) is performed by sub-processors that may operate outside India. We disclose this in our Privacy Policy rather than claim full data localisation.

3 Infrastructure

The Service runs on reputable cloud and telephony providers. We apply security updates to our systems, separate production from development where practical, and design for tenant isolation across a shared, capacity-managed worker pool. We rely on our providers' physical and network security at the infrastructure layer.

4 Shared responsibility

Security is shared. We secure the platform; you secure your use of it:

5 Reliability and backups

We take operational measures to keep the Service available and to back up critical data. No service can guarantee zero downtime or data loss; our commitments on availability are set out in the Terms of Service.

6 Reporting a vulnerability

Found a security issue?

We welcome reports from researchers and users. Please email dhipinkumar@gmail.com with details and steps to reproduce. We ask that you give us a reasonable opportunity to investigate and fix the issue before any public disclosure, and that you avoid accessing or modifying other people's data during testing.

We will acknowledge valid reports and keep you informed of our progress. We do not currently operate a paid bounty programme, but we are glad to credit researchers who report responsibly. Please do not place test calls to numbers you do not own, or run load tests against the dialler.

7 Incident response

If we become aware of a security incident affecting personal data, we will investigate, take steps to contain and remediate it, and notify affected customers and authorities where required by law, within applicable timeframes.

8 Contact