Security

Effective 10 May 2026.

Security and privacy are foundational. This page summarises our controls and the path to disclose vulnerabilities.

Encryption

  • TLS 1.2/1.3 in transit (HSTS preload).
  • AES-256 at rest. Optional AWS KMS customer-managed keys for HIPAA tenants.
  • SIP TLS 5061 + SRTP for any tenant with encryptionPolicy = require_srtp_tls.
  • WebRTC insertable streams enable end-to-end-encrypted video meetings when e2eeEnabled.
  • Bcrypt (12 rounds) for user passwords. Sha-256 for API key hashes (raw key shown once).

Access control

  • Asterisk AMI bound to loopback only; never exposed publicly.
  • Internal endpoints (push forwarder, scam-shield screen, power-dialer claim) refuse non-loopback callers.
  • Per-tenant ownership enforced server-side on every call-control method (channel context check before AMI action).
  • SAML SSO (Okta, Azure AD, Google) for enterprise tenants.
  • Two-factor authentication via SMS OTP available on every account.

Audit

All admin and security-relevant actions write a TenantActivityLog entry. Retention is 12 months on standard tenants, 6 years on HIPAA tenants (immutable).

Penetration testing

Annual external test by a CREST-certified provider. Latest summary: SOC 2-aligned controls, 0 critical findings, 2 medium findings closed, May 2026.

Vulnerability disclosure

Email security@siluxcall.co.uk, see /.well-known/security.txt. We acknowledge in 24h, triage in 5 days, and resolve in 30. Researchers acting in good faith are not pursued under the Computer Misuse Act.

Hall of Fame

Researchers who have responsibly disclosed issues are listed here once their finding is resolved.


Silux Telecom Ltd is a company registered in England & Wales. UK GDPR / Data Protection Act 2018 controller: Silux Telecom Ltd. ICO registration: pending.