Security and compliance

WebCallHub calls are encrypted in transit with DTLS-SRTP, the same media encryption used by Google Meet, Microsoft Teams and Zoom, and all signaling and dashboard traffic runs over TLS. Primary infrastructure is in the US, EU data residency is available on Business plans, and we sign a DPA on request.

Encryption

Voice media uses WebRTC with DTLS-SRTP. Encryption keys are negotiated by the browsers themselves over a DTLS handshake, so the media stream is encrypted from the moment it leaves the caller's browser.

Signaling, the dashboard and every API call run over TLS. Recordings and transcripts are encrypted at rest.

Access control

  • Agent seats are individual logins — no shared accounts
  • Role separation between owners, tenant admins and agents
  • Audit logging for call events
  • Encrypted storage on paid plans
  • SSO/SAML is on the Enterprise roadmap and not yet available

Data protection

  • A Data Processing Agreement is available on request
  • Data deletion requests are honoured within 30 days
  • We do not sell user data and do not track visitors across sites
  • Call recording is consent-based and can be disabled entirely
  • Primary infrastructure is US-based; EU data residency is available on Business plans

Frequently asked questions

Is WebCallHub call audio encrypted?

Yes. WebRTC media is encrypted with DTLS-SRTP and signaling runs over TLS. Recordings and transcripts are encrypted at rest.

Where is WebCallHub data stored?

Primary infrastructure is in the United States, under US data protection law. EU data residency is available on Business plans.

Is WebCallHub GDPR compliant?

Yes. We sign a DPA on request, honour deletion requests within 30 days, never sell user data and do not track visitors across sites.

Can call recording be turned off?

Yes. Recording is consent-based and can be disabled entirely for compliance reasons.

Talk to us about your requirements