CallXTime Security
Security practices and compliance overview for CallXTime.
Last Updated: July 22, 2026
Operated by: Arohva Global
CallXTime, operated by Arohva Global, is built for sales and revenue teams that handle sensitive customer and communications data every day. This page describes the technical and organizational measures we use to protect confidentiality, integrity, and availability across our power dialer, CRM, messaging, meetings, and automation platform.
Security is a shared responsibility: we secure the platform; you configure workspace access, integrations, and data handling for your organization. Enterprise customers may request additional due-diligence materials via [email protected].
1. Our Security Commitment
Protecting customer trust is foundational to CallXTime. We apply layered (“defense in depth”) controls spanning cloud infrastructure, application architecture, identity, data protection, monitoring, and incident response.
Our objectives:
- Keep Customer Data confidential within the correct tenant boundary
- Maintain integrity of records, configurations, and communications metadata
- Preserve availability appropriate for a business-critical sales platform
- Continuously improve controls as threats and product capabilities evolve
We align our practices with widely recognized frameworks used by B2B SaaS providers and are pursuing formal assurance programs (including SOC 2 Type II) as part of our compliance roadmap.
2. Shared Responsibility Model
CallXTime is responsible for:
- Securing the multi-tenant application, APIs, and underlying cloud infrastructure we operate
- Encrypting data in transit and at rest in platform-managed stores
- Enforcing tenant isolation and platform authentication mechanisms
- Monitoring for abuse and responding to platform-level incidents
You (the customer) are responsible for:
- User lifecycle management, role assignments, and least-privilege access inside your workspace
- Protecting end-user devices, browsers, and credentials (including MFA where available)
- Lawful collection and use of Customer Data and communications consent
- Secure configuration of integrations (Google, Microsoft, WhatsApp, telephony) and timely revocation when Users leave
- Classifying and exporting data according to your internal policies
Misconfiguration of roles or sharing of credentials can undermine otherwise strong platform controls.
3. Cloud Infrastructure & Network Security
CallXTime runs on reputable cloud infrastructure with hardened network boundaries and operational controls.
- Production environments are separated from development and staging
- Network segmentation, firewall rules, and restricted administrative pathways
- Patch management and vulnerability remediation for infrastructure components
- Redundant storage and availability planning appropriate to service tier
- Continuous uptime monitoring and operational alerting
Physical security of data centers is managed by our cloud providers under their compliance programs; we rely on those attestations for physical controls.
4. Data Encryption
We protect data using industry-standard cryptography:
- TLS 1.2+ for data transmitted between browsers, mobile/desktop clients, APIs, and integrations
- Encryption at rest for primary databases and object storage used by the platform
- Passwords stored using modern salted hashing algorithms — never plaintext
- Payment card data handled by PCI-compliant payment processors; CallXTime does not store full PAN data
- OAuth refresh/access tokens stored with restricted access and used only to provide authorized integration features
Key management follows provider best practices; access to decryption material is limited to authorized systems and personnel.
5. Tenant Isolation & Access Control
CallXTime is multi-tenant. Customer Data is logically isolated at the application layer:
- Every authenticated request is scoped to a tenant (workspace)
- Authorization checks enforce role-based access control (RBAC) within that tenant
- Administrative and support access to production Customer Data is restricted, logged, and used only when necessary (for example, to resolve a ticket you open)
- Optional enterprise identity features (SSO) may be available depending on plan
Workspace administrators should regularly review Users, roles, API keys, and connected integrations.
6. Authentication & Session Management
Authentication supports secure sign-in flows including email/password and OAuth identity providers (such as Google and Microsoft) where enabled.
- Sessions use secure cookies / tokens with validation on protected routes
- Multi-factor authentication may be available depending on plan and configuration — we recommend enabling MFA for administrators
- Account lockout and abuse-prevention controls help mitigate credential stuffing
- Users and admins can revoke third-party integration access at any time
- Offboarding Users promptly is essential to reduce residual access risk
7. Secrets, Credentials & OAuth Tokens
Platform secrets (database credentials, API keys, signing secrets) are stored using secure secret management practices and are not embedded in client-side code.
For customer-connected Google and Microsoft accounts:
- Tokens are stored server-side with restricted access
- Tokens are used only for scopes you approved and features you enabled (for example, Gmail send, Calendar events, and optional Contacts readonly)
- Disconnecting an integration invalidates ongoing API use from CallXTime
- We do not use Google user data in ways prohibited by Google’s Limited Use requirements (see Privacy Policy)
Customers should rotate any customer-managed API keys if compromise is suspected.
8. Application Security & Secure Development
We follow secure software development practices intended to reduce common application risks:
- Code review and controlled deployment pipelines
- Input validation and protections against common web vulnerabilities (OWASP Top 10 class issues)
- Dependency monitoring and timely patching of critical libraries
- Rate limiting and abuse detection on public and sensitive endpoints
- Segregation of privileged operations from standard user flows
- Least-privilege service accounts for background jobs and workers
Security findings from testing or reports are tracked to remediation.
9. Logging, Monitoring & Threat Detection
Operational and security-relevant events are logged to support investigations, customer support, and compliance reviews.
- Audit trails for administrative and sensitive actions where implemented
- Centralized monitoring and alerting for availability and anomalous behavior
- Retention of logs for operational security periods
- Correlation of signals to detect abuse (spam, credential attacks, unusual API volume)
Logs may contain limited personal information (such as IP addresses or User identifiers) and are protected under our Privacy Policy.
10. Backup, Continuity & Disaster Recovery
We maintain backup and recovery practices designed to restore Service data after failure scenarios:
- Regular automated backups of critical data stores
- Backup encryption and access restrictions
- Documented recovery procedures for infrastructure and application components
- Periodic review of restore capabilities as part of operational readiness
Recovery Time Objective (RTO) and Recovery Point Objective (RPO) targets may vary by incident class and plan. Customers requiring contractual uptime commitments should discuss SLA options with sales.
11. Incident Response & Breach Notification
We maintain an incident response process for identifying, containing, eradicating, and recovering from security events.
- Defined severity levels and escalation paths
- Evidence preservation for significant incidents
- Post-incident review and corrective actions
- Customer notification of confirmed personal data breaches affecting Customer Data as required by applicable law and contractual obligations
If you suspect unauthorized access to your workspace, contact [email protected] and [email protected] immediately, reset credentials, and revoke unused integrations.
12. Compliance, Privacy & Assurance
CallXTime designs controls to support enterprise due diligence for B2B SaaS:
- Privacy practices described in our Privacy Policy (/privacy), including Google Limited Use commitments for Gmail send, Calendar, and Contacts OAuth data
- GDPR-aligned processing roles (controller/processor) and DPA availability for enterprise customers
- Roadmap toward SOC 2 Type II and continuous control improvement
- Configurable retention and deletion options where product features allow
Formal certifications, pen-test summaries, and detailed control matrices may be shared under NDA with qualified prospects and customers.
13. Subprocessors & Third-Party Risk
We use vetted subprocessors for hosting, telephony, email delivery, payments, analytics, and support tooling. Vendors are evaluated for security posture and bound by contractual confidentiality and data-protection terms appropriate to their role.
When you connect third-party integrations, CallXTime accesses only the data required for features you enable. Third-party outages or policy changes are outside our direct control; we work with providers to restore service where possible.
A subprocessors overview is available to enterprise customers upon request.
14. Personnel Access & Training
Access to production systems and Customer Data by Arohva Global personnel is granted on a least-privilege, need-to-know basis.
- Background checks where legally permitted and appropriate for role
- Confidentiality obligations for employees and contractors
- Security awareness expectations for engineering and support teams
- Access reviews and revocation when roles change
Support access is typically performed only in response to a customer request or to remediate a platform issue.
15. Vulnerability Disclosure
If you discover a potential security vulnerability in CallXTime, please report it responsibly to [email protected] (and [email protected]) with enough detail to reproduce the issue.
Please:
- Do not access or modify data that is not yours
- Do not disrupt Service availability (no DDoS testing without written approval)
- Allow us a reasonable time to investigate and remediate before public disclosure
We appreciate good-faith research and will acknowledge valid reports. We do not permit social engineering of our employees or customers as part of testing without prior written authorization.
16. Contacting Security
Security: [email protected] Privacy: [email protected] General: [email protected] Web: https://callxtime.com/contact
Related pages: Privacy Policy (/privacy) · Terms of Service (/terms)
Operator: Arohva Global (CallXTime)