Security & compliance

The checks run before the phone rings.

Calling rules in India are about what happens before a call, not after it. So the checks live in the dialler itself: every call is checked before it is placed, and the result is recorded — including the calls it refused.

Before every dial

Nothing is handed to the phone carrier to dial on its own. Every call — by a person or by the agent — passes a check first, and the check is written down whether the call goes ahead or not.

DND, at the moment of dialling
The registry is checked when a call is placed, not once at upload. An answer we could not get is treated as unknown, never as clear.
Calling hours
09:00 to 21:00 in your organisation's time zone. Outside them, the agent does not dial.
Attempt limits
A cap on how many times a lead is tried, and outcomes such as Do Not Call stop all further dialling.
A record of every attempt
Each check is stored append-only, including the calls it refused — so you can show what was blocked and why.

On the call

It never claims to be human
It announces it is an AI at the start of the call by default, and says so whenever it is asked. That second part is fixed in the product, not a setting anyone can turn off.
No sensitive asks
It is built never to ask for PAN, Aadhaar, bank details or an OTP.
Approved facts only
Product details reach a call only after someone on your team approves them.
Two off switches
The agent cannot dial unless it is switched on in the CRM and in the voice service separately — either one alone keeps it silent.

Who sees what

Roles and permissions
Every screen and action is tied to a permission, and data is filtered in the database query itself — a telecaller sees their own leads, not everyone's.
Masked numbers
Phone numbers are masked for anyone whose role does not include seeing them, including in exports and the activity log.
Recordings
Played through short-lived signed links, never a public address. A recording can be deleted, and stays deleted.
No government IDs
There is no field for PAN, Aadhaar or any other government ID, so that data is never collected at all.

What we do not claim

We do not hold a SOC 2 or ISO certification yet, and we will say where the data is hosted once the service is deployed there. The privacy policy describes what is collected and why.