How your calls and your credentials are handled
Bots dial from your dialer on your caller ID, so the calls, the consent and the recordings stay in your stack. What B3 Voice holds is your configuration, your orders and your invoices, and everything below describes a mechanism in the product, not an intention.
B3 Voice encrypts each dialer connection’s credentials at rest with AES-256-GCM, scopes every query to the client record that owns it, enforces permissions server-side and revokes sessions on the next request. Uploaded payment proofs sit in private storage behind signed links. It is not SOC 2 or ISO 27001 certified.
The controls behind a call
Seven mechanisms, described at the level a security reviewer can check rather than the level a brochure usually stops at.
Your dialer credentials, encrypted per connection
The credentials that let a bot reach your dialer or SIP trunk are stored against that one connection and encrypted at rest with AES-256-GCM, each record carrying its own salt, initialisation vector and authentication tag. They are decrypted only at the moment a call is placed, and they are never returned to the browser once saved.
Client-scoped data isolation
Every query is scoped to the client record that owns it, orders, invoices, payments, uploaded transfer proofs and campaign configuration alike. Isolation is enforced at the data layer on each request rather than relied upon from the interface, so another center's record cannot be reached by guessing an identifier.
Separate staff and client access
The back office and the client panel are different roles with different permissions, checked server-side on every action rather than hidden in the interface. A client account can only ever see its own orders and invoices; a staff account cannot sign into the client panel in a customer's place.
Sessions you can revoke immediately
Revocation is enforced on every request rather than waiting for a token to expire. When a session is revoked or a person is removed, their access stops at their next request, which is what makes an offboarding or a lost laptop something you can actually act on.
Payment proofs in private storage
Bank transfer receipts uploaded against an invoice are held in private object storage, never in a public bucket, and are reachable only through short-lived signed links issued to the client who uploaded them and to the staff confirming the payment.
Your script is yours
The script, disclosure and rebuttals you send are used to build your call flow and nothing else. They are not shared with another client, not used to build a bot for another floor, and are deleted on request along with the rest of your record.
Consent and recording stay with you
Bots dial from your dialer, on your caller ID, against the list you supply and the suppression file you maintain, so TCPA consent, calling windows and do-not-call obligations remain yours. The bot reads the disclosure you give it, verbatim, on every call, which is the part a floor usually cannot guarantee.
The certifications we do not hold
Published deliberately. You would ask anyway, and a supplier who answers this before the questionnaire arrives is easier to work with than one who does not.
SOC 2
B3 Voice is not currently SOC 2 certified and no audit report is available. The controls described above are implemented, but they have not been examined by an independent auditor.
ISO 27001
B3 Voice is not currently ISO 27001 certified. If a certified supplier is a hard requirement for your procurement process, say so early and we will tell you plainly where that leaves us.
HIPAA
No business associate agreement is offered, so bots must not be used to collect protected health information under US HIPAA. Medicare and ACA bots take the qualifying answers the campaign requires, age band, Part A and B status, household size, and nothing clinical.
Data residency
Processing is not restricted to a single region today. The call itself stays in your own dialer and carrier; what we process is the configuration, the orders and the invoices, through providers some of which operate outside your country. The role and region of each is published on the sub-processors page, and specific residency requirements should be raised before you sign.
If a certified supplier is a hard procurement requirement, say so in your first email rather than your fifth, we will tell you plainly where that leaves us. Security questions and vulnerability reports both go to [email protected].
What stays with you
Some of this is not ours to do, and pretending otherwise would leave you exposed.
You are the caller of record
Calls leave your own dialer on your own caller ID, so to the person receiving one the call is from your center. Consent, calling windows and do-not-call obligations sit with you.
You decide what is recorded
Recording, transcription and retention are settings you control. Telling people on the call that it is recorded is your obligation under UK GDPR and PECR, including calls your own team answers under human-first routing.
You control who has access
Roles, sessions and who on your team can see invoices are managed in the client panel. Revoking a session takes effect on that person's next request, which is what makes offboarding something you can act on immediately.
