Security
What protects your calls, texts and recordings. Measured on our production servers on 21 September 2026, not assumed.
Encryption in transit
- Website, app and API: TLS 1.3, with TLS 1.2 as the fallback (ECDHE, AES-256-GCM). TLS 1.0 and 1.1 are refused. HSTS is on for a year including subdomains; plain HTTP redirects to HTTPS.
- Calls from the web and mobile apps: the audio between your device and our media servers is DTLS-SRTP (DTLS 1.2 with AES-128-GCM key exchange; SRTP AES-256-GCM or AES-CM-128-HMAC-SHA1-80), measured in a real browser.
- Between our own servers: a WireGuard tunnel (ChaCha20-Poly1305). The database accepts connections only inside that tunnel.
What is not encrypted, said plainly
The leg between our servers and the telephone carrier (SIP signalling and RTP audio) is not encrypted today, which is the usual state of the public telephone network: the moment a call leaves any provider for a landline or a mobile it travels unencrypted anyway. Desk phones connect with SIP digest authentication and no TLS or SRTP; encrypting that leg depends on the handset model and is on our list. Calls placed and answered in the web and mobile apps are encrypted all the way to our servers.
Encryption at rest
- Disks: every server disk is LUKS2 full-disk encryption, AES-256 (XTS), with the key held in the machine's TPM.
- Recordings and backups: encrypted with AES-256 under a key derived from a separate key file (PBKDF2-HMAC-SHA256) before they are stored, locally and in the offsite backup store.
- Passwords: bcrypt. Sessions are signed tokens. Webhooks from the carrier are signature-verified (Ed25519).
Backups and recovery
Encrypted backups go offsite daily and are kept for 30 days. A restore from backup is tested every week on a separate machine. When a recording is deleted, the offsite copy is deleted with it.
Sign-in and access
- Two-step sign-in (an authenticator app code) is available to every account and recommended for owners and administrators.
- Each company has an activity log of who listened to a recording, exported a call log, changed a role or a compliance setting.
- AIMERICA staff access to a customer account is logged.
- Rate limits and security headers are in place; dependencies are audited.
Where your data lives
Miami, Florida, United States, on servers we rent from ReliableSite. Nothing is stored outside the United States. Customers in Quebec: the transfer assessment Law 25 asks for is available on request.
Subprocessors
| Provider | Where | What for |
|---|---|---|
| Telnyx | United States | Phone numbers, calls, texts, faxes and 911 routing (the carrier) |
| Deepgram | United States | Speech to text: transcripts and the AI receptionist's hearing |
| Cartesia | United States | Text to speech: the AI receptionist's voices |
| OpenAI | United States | Language models behind the AI receptionist and summaries |
| Anthropic | United States | Language models behind AI assistance and summaries |
| Finix | United States | Card payments: the platform's own invoices and AIMERICA Payments |
| ReliableSite | United States (Miami, Florida) | The servers everything runs on and the encrypted offsite backup store |
We tell customers with a data-processing agreement 30 days before a subprocessor is added.
Monitoring
Calls, call quality, voicemail, the app and the website are checked every five minutes by the same monitoring that pages our engineers; a real test call goes through the carrier five times a day. The status page shows the result and 90 days of history.
Reports and questionnaires
We do not hold a SOC 2 or ISO 27001 report today. We answer security questionnaires from the facts on this page; write to sales@a1merica.ai. To report a security problem, use the same address and put "security" in the subject; we answer within two business days.
Health information (HIPAA)
AIMERICA does not sign business associate agreements today. Do not use the service for protected health information.
