Calling Bees
Back home

Security at Calling Bees

We handle live phone calls, transcripts, and CRM data on behalf of our customers. Here's how we protect that information end-to-end.

Compliance

We are not currently SOC 2 certified and cannot sign BAAs for HIPAA-regulated workloads. We can complete most enterprise security questionnaires within five business days, and are happy to walk through our controls in detail.

Encryption

TLS 1.2+ in transit. AES-256 at rest in PostgreSQL and S3. Per-workspace telephony credentials are encrypted with a separate key — even our database administrators cannot read them in plaintext.

Infrastructure

Hosted on AWS. Network isolation by VPC, no public database exposure, automatic backups with point-in-time recovery, and 24/7 infrastructure monitoring.

Access controls

Least-privilege RBAC across the platform. Mandatory SSO + 2FA for the engineering team. Production access is audited and time-bound.

Data handling

Tenant data is row-isolated by workspace. Recordings live in a dedicated bucket with object-level ACLs. Customers can request deletion at any time and we honor it within 30 days.

Vendor management

Every sub-processor (Twilio, LiveKit, OpenAI, Deepgram, AWS, Stripe) is reviewed for security posture before onboarding. Full sub-processor list available on request.

Reporting a vulnerability

If you've found a security issue, please email security@callingbees.io with reproduction steps. We respond within one business day and treat all reports confidentially. We don't currently offer a bounty but we'll publicly thank reporters who consent to it.

Documentation on request

For our security control documentation, sub-processor lists, or our DPA, contact security@callingbees.io. We typically share these under NDA.