Vistrow Voice
Security & trust

Phone calls are sensitive. We treat them that way.

Vistrow Voice handles recordings, transcripts, and personal details captured on live calls. This page lists the controls that exist today - and, at the bottom, the ones that don’t yet.

Workspace isolation

Dashboard queries for calls, contacts, agents, recordings, and knowledge bases are scoped to the authenticated workspace. Access-control defects are treated as security incidents and investigated promptly.

Credential handling

Passwords are stored only as salted hashes, never in readable form. Sessions use signed, expiring tokens in HTTP-only cookies. API keys are shown once, then stored hashed, and can be revoked at any time.

Role-based access

Team members are invited into your workspace with a role. Only owners can change billing, compliance settings, and destructive configuration.

Do-Not-Call enforcement

Your DNC registry is a hard block checked before any outbound dial leaves the platform. A blocked number is never dialled - a call can’t be un-rung, so the gate runs first.

Calling-window rules

Outbound calling is restricted to the hours and days you configure. Dials attempted outside that window are refused and logged rather than placed.

Configurable retention

Set a retention period and call records older than it are purged automatically - data minimisation under the DPDP Act rather than keeping everything forever by default.

Recording access control

Call recordings are not publicly addressable. Playback goes through short-lived signed URLs issued only to authenticated members of the owning workspace.

No vendor surface

Our agents are built to decline questions about the underlying models and speech stack. Your callers - and your competitors - can’t extract our architecture from a conversation.

No card data

Online checkout is not enabled during public testing. The platform therefore does not collect or store full card numbers.

Who controls what

Your data stays yours.

You are the controller

You decide who gets called, what the agent says, what it captures, and how long any of it is kept. Recordings, transcripts, and lead data belong to your business.

We are the processor

We process that data to run the service you configured - nothing else. We don’t sell it, and we don’t use your call content to train models for other customers.

The full legal detail lives in our Privacy Policy and Terms.

What we don’t claim yet

The gaps, stated plainly.

Plenty of vendors imply certifications they don’t hold. We’d rather you find out here than in a procurement review.

  • A formal SOC 2 Type II audit - not yet started; we will publish the report when it exists rather than implying it now.
  • India-region data residency - call data is currently processed and stored outside India. If in-country residency is a requirement for you, tell us before you sign so we can be straight about timelines.
  • A published third-party penetration-test summary.

Found a vulnerability?

Report it to us privately and we’ll acknowledge it. Please don’t test against live tenant data or place real calls as part of any testing.

Report a security issue
Live demo

Put an AI agent on every call.

Try Artha live in your browser, or book a walkthrough with our team.

  • No signup needed
  • 5 free calls
  • 87 languages