Security
Effective 10 May 2026.
Security and privacy are foundational. This page summarises our controls and the path to disclose vulnerabilities.
Encryption
- TLS 1.2/1.3 in transit (HSTS preload).
- AES-256 at rest. Optional AWS KMS customer-managed keys for HIPAA tenants.
- SIP TLS 5061 + SRTP for any tenant with
encryptionPolicy = require_srtp_tls. - WebRTC insertable streams enable end-to-end-encrypted video meetings when
e2eeEnabled. - Bcrypt (12 rounds) for user passwords. Sha-256 for API key hashes (raw key shown once).
Access control
- Asterisk AMI bound to loopback only; never exposed publicly.
- Internal endpoints (push forwarder, scam-shield screen, power-dialer claim) refuse non-loopback callers.
- Per-tenant ownership enforced server-side on every call-control method (channel context check before AMI action).
- SAML SSO (Okta, Azure AD, Google) for enterprise tenants.
- Two-factor authentication via SMS OTP available on every account.
Audit
All admin and security-relevant actions write a TenantActivityLog entry. Retention is 12 months on standard tenants, 6 years on HIPAA tenants (immutable).
Penetration testing
Annual external test by a CREST-certified provider. Latest summary: SOC 2-aligned controls, 0 critical findings, 2 medium findings closed, May 2026.
Vulnerability disclosure
Email info@siluxcall.co.uk, see /.well-known/security.txt. We acknowledge in 24h, triage in 5 days, and resolve in 30. Researchers acting in good faith are not pursued under the Computer Misuse Act.
Hall of Fame
Researchers who have responsibly disclosed issues are listed here once their finding is resolved.
Silux Telecom Ltd is a company registered in England & Wales. UK GDPR / Data Protection Act 2018 controller: Silux Telecom Ltd. ICO registration: pending.