- Home
- Security
Updated 2026-09-28
The controls that exist today.
Calls, recordings and lead lists deserve care. This page lists the specific protections in the product right now, and what we do not have yet. No badges we have not earned.
Access
- Recordings behind sign-in
- Call recordings stream only to a signed-in user with an operator, VA or admin role. There is no public recording link.
- Roles
- Admin, agent and VA roles limit who can manage users, export leads and change workspace settings.
- Sign-in lockout
- Six failed sign-ins on an account trigger a five-minute block.
- Rate limits
- Sign-in, sign-up, token refresh, password reset and inbound carrier webhooks are rate limited per client.
Sessions and tokens
- Refresh token rotation
- Refresh tokens are stored hashed and rotate on every use. Replaying an old token revokes every session for that user.
- Single-use stream tickets
- The live dialer event stream uses one-time tickets that expire in about a minute, so no bearer token ever sits in a URL.
- Password resets
- Reset links are single use and expire.
Webhooks and secrets
- Signed carrier webhooks
- Every Telnyx call event is checked against Telnyx's ed25519 signature before it is processed.
- Signed outbound webhooks
- Disposition events you receive carry an HMAC-SHA256 signature over the timestamp and body.
- Encrypted credentials
- Carrier credentials stored for a workspace are encrypted at rest with AES-256-GCM.
Transport and browser
- HTTPS only
- Plain HTTP redirects to HTTPS, with TLS 1.2 as the minimum.
- HSTS
- dialbreeze.com and app.dialbreeze.com send Strict-Transport-Security, so browsers refuse to downgrade.
- Content Security Policy
- The app restricts scripts, frames and connections to its own origin and cannot be framed by another site.
Not yet
- No SOC 2, ISO 27001 or HIPAA attestation. We will say so here when that changes.
- No single sign-on (SAML or OIDC) yet.
- No customer-configurable data retention period yet. Ask before uploading production data if you need one.
Security questions.
See also the privacy policy and the DNC policy.
Where are recordings stored?
Recordings are fetched from your carrier and stored by DialBreeze for playback and after-call processing. Playback requires a signed-in user. Ask us before production use if you need a specific retention period, deletion process or processor agreement.
Do you have SOC 2?
No. DialBreeze has no third-party security certification today. This page lists the controls that exist in the product, each of which you can ask us to demonstrate during the trial.
Who can see my leads?
Users in your workspace, according to their role. The privacy policy explains how support access to workspace data is handled.
How do I report a security issue?
Email brayden@themilnerteamfl.com with the details. We read every report and will reply.
Ask us to show you.
Any control on this page can be demonstrated during the 14-day sandbox trial.