Trust & Security
Security is a first-class feature.
This page is maintained by OttoCall to answer common security and privacy questions. It is not an independent certification.
Encryption in transit
Voice and web traffic use industry-standard TLS/SRTP encryption between clients and OttoCall infrastructure.
Access controls
Role-based permissions, admin audit logs and support for SSO (SAML) on enterprise plans.
Least-privilege operations
Internal access to production systems is scoped, logged and reviewed.
Business continuity
Geographically redundant infrastructure with documented failover procedures.
Data processing agreements
DPAs and country-specific addenda are available on request for regulated industries.
Vulnerability reporting
Report security issues to security@ottocall.com. Responsible disclosure is welcomed.
Shared responsibility. OttoCall secures the platform, network and application. Customers are responsible for account passwords, user provisioning, retention policies, and integrations they configure. Some regulatory frameworks (HIPAA, PCI-DSS, GDPR, SOC 2) require specific contractual and configuration steps — contact sales to review what your use case needs.
