Security
Controls built around every call.
AhoyDial separates browser audio, account authorization, provider events, prepaid accounting, and operations access so one compromised boundary does not silently rewrite another.
Accounts and organizations
- Verified sessions and organization-scoped authorization protect customer resources.
- Passkeys and authenticator-based MFA are available for account protection.
- Sensitive wallet, security, invitation, and operations actions require a recent sign-in.
Calls and provider events
- Browser audio travels directly to the telephony provider and telephone network; AhoyDial does not relay or record it.
- Telephony credentials are short-lived and issued for an authorized call context.
- Provider webhooks are signature-verified, deduplicated, normalized, and processed idempotently.
Payments and wallet records
- Stripe Checkout handles payment-card entry; AhoyDial does not receive full card numbers or CVCs.
- Wallet value uses integer minor units and balanced append-only journal entries.
- Reservations, settlements, releases, refunds, disputes, and adjustments remain separate auditable events.
Report a vulnerability
Send a concise description, affected URL, reproduction steps, and potential impact. Do not access other customers’ data, disrupt calls, or perform destructive testing.
Send a security report