AI-Powered Sales Acceleration Platform

CallXTime Security

Security practices and compliance overview for CallXTime.

Last Updated: July 22, 2026

Operated by: Arohva Global

CallXTime, operated by Arohva Global, is built for sales and revenue teams that handle sensitive customer and communications data every day. This page describes the technical and organizational measures we use to protect confidentiality, integrity, and availability across our power dialer, CRM, messaging, meetings, and automation platform.

Security is a shared responsibility: we secure the platform; you configure workspace access, integrations, and data handling for your organization. Enterprise customers may request additional due-diligence materials via [email protected].

1. Our Security Commitment

Protecting customer trust is foundational to CallXTime. We apply layered (“defense in depth”) controls spanning cloud infrastructure, application architecture, identity, data protection, monitoring, and incident response.

Our objectives:

We align our practices with widely recognized frameworks used by B2B SaaS providers and are pursuing formal assurance programs (including SOC 2 Type II) as part of our compliance roadmap.

2. Shared Responsibility Model

CallXTime is responsible for:

You (the customer) are responsible for:

Misconfiguration of roles or sharing of credentials can undermine otherwise strong platform controls.

3. Cloud Infrastructure & Network Security

CallXTime runs on reputable cloud infrastructure with hardened network boundaries and operational controls.

Physical security of data centers is managed by our cloud providers under their compliance programs; we rely on those attestations for physical controls.

4. Data Encryption

We protect data using industry-standard cryptography:

Key management follows provider best practices; access to decryption material is limited to authorized systems and personnel.

5. Tenant Isolation & Access Control

CallXTime is multi-tenant. Customer Data is logically isolated at the application layer:

Workspace administrators should regularly review Users, roles, API keys, and connected integrations.

6. Authentication & Session Management

Authentication supports secure sign-in flows including email/password and OAuth identity providers (such as Google and Microsoft) where enabled.

7. Secrets, Credentials & OAuth Tokens

Platform secrets (database credentials, API keys, signing secrets) are stored using secure secret management practices and are not embedded in client-side code.

For customer-connected Google and Microsoft accounts:

Customers should rotate any customer-managed API keys if compromise is suspected.

8. Application Security & Secure Development

We follow secure software development practices intended to reduce common application risks:

Security findings from testing or reports are tracked to remediation.

9. Logging, Monitoring & Threat Detection

Operational and security-relevant events are logged to support investigations, customer support, and compliance reviews.

Logs may contain limited personal information (such as IP addresses or User identifiers) and are protected under our Privacy Policy.

10. Backup, Continuity & Disaster Recovery

We maintain backup and recovery practices designed to restore Service data after failure scenarios:

Recovery Time Objective (RTO) and Recovery Point Objective (RPO) targets may vary by incident class and plan. Customers requiring contractual uptime commitments should discuss SLA options with sales.

11. Incident Response & Breach Notification

We maintain an incident response process for identifying, containing, eradicating, and recovering from security events.

If you suspect unauthorized access to your workspace, contact [email protected] and [email protected] immediately, reset credentials, and revoke unused integrations.

12. Compliance, Privacy & Assurance

CallXTime designs controls to support enterprise due diligence for B2B SaaS:

Formal certifications, pen-test summaries, and detailed control matrices may be shared under NDA with qualified prospects and customers.

13. Subprocessors & Third-Party Risk

We use vetted subprocessors for hosting, telephony, email delivery, payments, analytics, and support tooling. Vendors are evaluated for security posture and bound by contractual confidentiality and data-protection terms appropriate to their role.

When you connect third-party integrations, CallXTime accesses only the data required for features you enable. Third-party outages or policy changes are outside our direct control; we work with providers to restore service where possible.

A subprocessors overview is available to enterprise customers upon request.

14. Personnel Access & Training

Access to production systems and Customer Data by Arohva Global personnel is granted on a least-privilege, need-to-know basis.

Support access is typically performed only in response to a customer request or to remediate a platform issue.

15. Vulnerability Disclosure

If you discover a potential security vulnerability in CallXTime, please report it responsibly to [email protected] (and [email protected]) with enough detail to reproduce the issue.

Please:

We appreciate good-faith research and will acknowledge valid reports. We do not permit social engineering of our employees or customers as part of testing without prior written authorization.

16. Contacting Security

Security: [email protected] Privacy: [email protected] General: [email protected] Web: https://callxtime.com/contact

Related pages: Privacy Policy (/privacy) · Terms of Service (/terms)

Operator: Arohva Global (CallXTime)