How Call Clearance handles your data
What we do today, stated only as far as it is true. No certification is held yet; nothing here claims one.
In transit and at rest
All connections use TLS. The database is on a Fly.io volume with encryption at rest enabled (verified Oct 7, 2026, volume callclearance_data, region iad).
Keys and secrets
Your Call Clearance API key is stored as a SHA-256 hash; we keep only a fingerprint and cannot show it again. Retell and Vapi platform keys you connect are encrypted with AES-256-GCM under a key derived (HKDF) from a server secret held outside the database, used only to place calls you send us, and deleted when you disconnect. Passwords are hashed with scrypt and a per-user salt.
Phone numbers
Numbers are stored only as keyed hashes (HMAC-SHA256 under a secret we hold). A number appears on a Call Record because it was supplied when the record was requested.
Records
Every record is chained to the one before it by SHA-256. Each day's closing fingerprint is published at api.callclearance.com/fingerprints and timestamped through OpenTimestamps on the Bitcoin blockchain, so a later change is detectable. The verifier is open source (MIT).
Backups and availability
Daily backups, kept 60 days, with a second copy pulled each morning. One hosting region today. The service is fail-closed: if a check does not answer, your software must not dial. See the status page.
Subprocessors
Fly.io (hosting, US), Cloudflare (website), Stripe (billing), Anthropic (the website help assistant only; conversations are not stored), the public OpenTimestamps calendars (receive only a hash), and, when you connect them, Retell and Vapi (to place your calls).
Reporting a security issue
Email [email protected] (placeholder: create this alias). We acknowledge within two business days.
Not yet
No SOC 2 or ISO 27001 certification. No signed DPA template yet (placeholder: lawyer-drafted DPA to be linked here). No bug bounty.