Legal
Security at WEBEE
Businesses trust WEBEE with their calls, conversations and customer data. Protecting that data is engineered into the platform, not bolted on.
Platform security
Encryption in transit
All traffic between your browser, our servers and our providers is encrypted with TLS. Voice media streams use the providers' encrypted transport.
Workspace isolation
Every workspace's data is segregated with row-level security enforced at the database layer — one tenant can never read another's data.
Access control
Role-based permissions, package entitlements and per-user overrides gate every sensitive action on the server, not just in the interface.
Approval gates
Consequential AI actions — deployments, campaigns, spending changes — require explicit human approval before they execute.
Operational practices
- Secrets and API credentials are stored in managed secret stores, never in source code or client bundles.
- Least-privilege service accounts and audited administrative access.
- Continuous health monitoring with automated alerting on abnormal behaviour.
- Third-party integrations (telephony, AI models, email) are accessed via scoped credentials that customers control per workspace.
- Single-use, signed, expiring authorisation flows for third-party account connections (e.g. Google).
Your part
Use strong, unique passwords, limit workspace membership to people who need it, and assign the least role required. Credentials for your own third-party accounts remain under your control and can be revoked at any time.
Reporting a vulnerability
If you believe you've found a security issue, please report it responsibly via our contact page with "Security" in the message. We investigate all reports and appreciate coordinated disclosure.
Ready to see WEBEE in action?
Launch AI voice agents, automate conversations and monitor performance from one platform.
