Security & Telecom Compliance.
Designed from the ground up for high-security enterprise telecalling teams. Indian data residency, military-grade AES-256 encryption, and verifiable legal admissibility.
Indian Data Residency
100% of audio recordings and lead records reside in Tier-4 Indian data centers (Mumbai region).
AES-256 & TLS 1.3
End-to-end encryption in transit (TLS 1.3) and military-grade AES-256 encryption at rest.
Section 65B Admissible
Cryptographic SHA-256 hashing preserves tamper-evident chain of custody for legal dispute resolution.
DPDP Act 2023 Ready
Full compliance with India's Digital Personal Data Protection Act and IT Intermediary Rules.
1. Cryptographic Call Audio Architecture
When telecallers use the AI Closer Android companion app, phone calls take place over genuine cellular GSM carrier networks (Airtel, Jio, Vi). To protect conversational privacy while guaranteeing data veracity:
- Local Dual-Channel Audio Capture: The raw audio recording is captured in high-fidelity Opus/AAC format directly on the device with zero cloud intermediary intercept during the active call.
- Immediate SHA-256 Checksum: As soon as the call terminates, our native engine generates a SHA-256 cryptographic digest of the audio payload before uploading.
- Encrypted Transport: The audio payload is streamed over TLS 1.3 using pre-signed secure AWS S3 URLs with short 15-minute expirations.
- Immutable Storage: Once uploaded, the audio file is committed to write-once, read-many (WORM) storage with AES-256 server-side encryption.
2. Multi-Tenant Isolation & Zero Cross-Contamination
Every customer account operates within a strictly segmented tenancy perimeter:
- Row-Level Security (RLS): Database queries enforce programmatic tenant ID boundaries at the database kernel level, making cross-tenant data leakage technically impossible.
- Role-Based Access Control (RBAC): Granular permissions prevent sales reps from viewing colleagues' leads, exporting client phone numbers, or deleting call audio records unless granted explicit administrative rights.
- Audit Logging: All administrative actions—including lead exports, user permission modifications, and audio access—are recorded in an immutable audit ledger.
3. WhatsApp & Meta Ecosystem Compliance
AI Closer combines official WhatsApp Cloud APIs with local Web QR synchronization. We strictly adhere to Meta developer terms:
- Official WhatsApp Cloud API: Template notifications and business broadcasts are routed through verified Meta Business Manager channels with end-to-end TLS encryption.
- Local QR Scanner Sandboxing: Personal WhatsApp Web QR sessions run within isolated browser sandboxes. Reps never need to disclose their master WhatsApp account credentials, and sessions are immediately revoked upon employee offboarding.
- Anti-Spam Throttling: Built-in rate limiting and opt-out workflows ensure compliance with WhatsApp Business messaging policies, preventing number bans.
4. Vulnerability Management & Penetration Testing
We maintain an aggressive defensive posture against evolving security threats:
- Continuous Automated SAST/DAST Scanning: Code repositories undergo automated static and dynamic security analysis prior to production release.
- Mobile APK Hardening: The Android application binary is protected with ProGuard/R8 obfuscation, anti-debugging defenses, and certificate pinning to prevent reverse engineering or APK tampering.
- DDoS & Web Application Firewall (WAF): Edge ingress traffic is routed through Cloudflare Enterprise WAF, filtering volumetric layer-7 attacks and malicious scraping bots.
Security Questionnaire & Compliance Inquiries
If your enterprise requires custom security audits, SOC2 vendor questionnaires, or Data Processing Agreements (DPA), please contact our security team:
Email: aicloser.in@gmail.com • WhatsApp: +91 95895 10954