An honest summary of how the platform is built and what protections are in place today. We do not claim certifications we do not hold.
Every domain table is workspace-scoped and protected by database-enforced row-level security. Authorization is enforced in the database, not just the UI — a compromised client cannot read another workspace's data. Platform-computed records (calls, call events, transcripts, usage) are read-only for tenants; only backend services can write them.
Workspace roles (owner, admin, manager, operator, member, viewer) gate sensitive actions; only owners can change roles, and privileged platform functions are executable only by backend service credentials. Sensitive administrative actions are written to an immutable audit log by database triggers.
Data is hosted in the Asia-Pacific (Mumbai) region and encrypted in transit (TLS). Storage encryption at rest is provided by our infrastructure providers. Secrets are kept server-side only and are never shipped to the browser. Phone numbers are masked in cross-tenant admin views and in operational logs.
There is no online checkout in the product and we never collect card or UPI details. Payment is arranged directly with our team outside the platform; we then record a reference to it — amount, method and date — against your workspace so your calling minutes can be activated. No payment instrument is stored.
The calling engine enforces per-workspace Do-Not-Call lists, optional consent-required calling, retry caps, and concurrency limits. There is no platform-mandated time-of-day restriction: outbound and inbound calling run 24×7 by default. Workspaces may optionally configure their own daily office-hours schedule to restrict outbound campaign and broadcast dialing (and its retries) to specific days and times; inbound calling is never restricted by it. Choosing when to call, within the hours permitted for your business, remains your responsibility.
We are an early-stage product. We do not currently hold SOC 2, ISO 27001, or similar certifications, and we do not yet offer a formal SLA. If a certification matters for your procurement, talk to us about our roadmap.
If you believe you have found a security issue, email support@samparkkaro.in with details. We acknowledge reports within 2 business days and will not pursue good-faith researchers.