---
title: "Security — CallsAround | TetraCore"
description: "CallsAround security overview: RLS tenant isolation, AES-256 encrypted OAuth tokens, Stripe-held payments, signed webhooks, scoped API keys, recording consent, retention, and audit logging."
lang: en
json-ld:
---

[![TetraCore Logo](/lovable-uploads/f8ea3e1f-4668-4dc0-aedd-6bfcdfc60d00.png)TetraCore ](/)

[Home](/)

[Products](/products)

[Services](/services)[About](/about)[Insights](/insights)[Support](/support)[Start a Project](/contact)

CallsAround is a [TetraCore](/) product — built in Ohio. [Full site: callsaround.com](https://callsaround.com)

CallsAround [Overview](/callsaround)[Product](/callsaround/product)[Features](/callsaround/features)[Emergency Dispatch](/callsaround/emergency-dispatch)[Reliability](/callsaround/reliability)[Industries](/callsaround/industries)[Pricing](/callsaround/pricing)[Case Study](/callsaround/case-study)[Security](/callsaround/security)[Book a Demo](/callsaround/contact)

Security

# The AI vendor is never a security boundary 

Tenancy, encryption, payment isolation, and audit are enforced in CallsAround's own systems — the voice model receives answers, never your credentials or customer data stores.

## Security controls

### Tenant isolation via RLS

Postgres Row-Level Security is the authoritative tenant boundary on every read and write. The AI voice vendor is never a security boundary — it receives answers, never credentials.

### Encrypted OAuth tokens

Customer Google/Microsoft OAuth tokens are AES-256-GCM encrypted at rest and never leave CallsAround servers.

### Payments stay with Stripe

Card data is held by Stripe, never by CallsAround. Billing state changes only from verified Stripe webhooks.

### Signed webhooks & scoped API keys

Inbound webhooks are signature-verified (Ed25519 for telephony, HMAC for Stripe). API keys are SHA-256-hashed at rest with scopes, rate limiting, and full request logging.

### Call-recording consent

A per-line disclosure toggle supports two-party-consent states. We do not sell personal data, and we do not use your calls to train AI models.

### Automatic data retention

Recordings and transcripts are kept 365 days, operational events 90 days, and API logs 30 days — then removed automatically.

### Audit log & session control

Every mutation is written to an audit log (who changed what). Session management includes "sign out of all devices," with Google/Microsoft SSO.

### Telephony compliance

E911 address support on every number, plus 10DLC and toll-free SMS compliance workflows.

CallsAround routes business  emergencies to your on-call team. It is not a substitute for 911.

Report a security issue: [security@tetracorehq.com](mailto:security@tetracorehq.com)

## Related CallsAround pages

-   [CallsAround overview](/callsaround) — AI receptionist and emergency dispatch.
-   [Product tour](/callsaround/product) — the receptionist, dispatch engine, and failover.
-   [Reliability & failover](/callsaround/reliability) — how dead air is made structurally impossible.
-   [Pricing](/callsaround/pricing) — per-line plans with security on every tier.
-   [Privacy policy](/callsaround/privacy) — what data we process and how.
-   [Book a security-focused demo](/callsaround/contact) — review controls against your requirements.

![TetraCore Logo](/lovable-uploads/f8ea3e1f-4668-4dc0-aedd-6bfcdfc60d00.png)TetraCore 

## Company

-   [Home](/)
-   [About](/about)
-   [Products](/products)
-   [Services](/services)
-   [Insights](/insights)
-   [Careers](/careers)
-   [Contact](/contact)
-   [Support](/support)

## Products

-   [FourSight](/products/foursight)
-   [LinkPilot](/products/linkpilot)
-   [VoterCXM](/products/votercxm)
-   [ItemStage](/itemstage)
-   [Franexis](/franexis)
-   [CallsAround](/callsaround)

## VoterCXM

-   [State Parties](/products/votercxm/state-parties)
-   [County Parties](/products/votercxm/county-parties)
-   [PACs](/products/votercxm/pacs)
-   [Voter Outreach](/products/votercxm/voter-outreach)

## Trust & Legal

-   [Privacy Policy](/privacy)
-   [Terms of Use](/terms)
-   [ItemStage Security](/itemstage/security)
-   [ItemStage Privacy](/itemstage/privacy)
-   [Franexis Security](/franexis/security)
-   [Franexis Privacy](/franexis/privacy)

© 2026 TetraCore. All rights reserved.

TetraCore — the Ohio software studio. Not affiliated with Tetracore, Inc. (biotechnology).

Empowering your digital future through AI-powered innovation.

Software Solutions Systems Security