Security
How we keep your phone (and your callers) safe.
We're an early-stage company; we don't have a SOC 2 report yet. Below is a plain accounting of what we do today. We update this page as we grow.
Encryption everywhere
Your data is encrypted in transit with modern TLS and encrypted at rest with AES-256. We do not keep plaintext call data or credentials sitting on disk.
Secrets stay secret
API keys and credentials live in a dedicated secrets manager with tightly scoped access. They are never committed to code and never emailed around in config files.
Locked-down access
Access to production is limited to a small team and protected by two-factor authentication. Administrative actions are logged and reviewed.
Your data is isolated
Each business's data is logically separated from every other customer's. Every request is authorized to your account only, so one business can never see another's calls or contacts.
Vetted providers
We rely on a small set of established, industry-standard providers to run the service. Their roles in handling data are described in our Privacy Policy.
Coordinated disclosure
Found a vulnerability? Email security@howdyly.com. We respond within one business day and won't pursue good-faith researchers who follow standard disclosure practice.
Questions or compliance review? Email security@howdyly.com.