Encryption
All voice streams are encrypted in transit via TLS 1.2+ and SRTP. Data at rest is encrypted using AES-256 with managed key rotation.
Isolation
Strict logical separation between Sandbox and Production nodes. Multi-tenant clusters utilize dedicated namespace isolation.
1. Access Controls
We enforce the principle of least privilege. Access to production environments requires multi-factor authentication (MFA) and is restricted to essential engineering personnel through just-in-time (JIT) access logs.
2. Logging and Monitoring
NexaVoxa maintains continuous observability over our global edge nodes. Any anomaly in latency, packet loss, or unauthorized API attempts triggers immediate automated escalation to our Security Operations Center (SOC).
3. Telephony Safeguards
SIP connections are hardened against toll-fraud and signaling attacks. We partner with Tier-1 carriers that utilize reputation-based filtering to prevent malicious use of our outbound nodes.
Report security vulnerabilities to [email protected]. We maintain a coordinated disclosure policy.