1. Security practices
- Encrypted connections (HTTPS/TLS) for web and API traffic
- Access controls on production systems and credentials
- Environment secrets stored outside application code
- Vendor due diligence for telephony, voice AI, and payment partners
No system is perfectly secure. We work to reduce risk and respond to incidents affecting customer data.
2. Data handling
Call metadata, transcripts, lead records, and account data are stored to operate the Service. See our Privacy Policy for retention and deletion requests.
3. Customer compliance
Business customers are responsible for compliance with laws applicable to their operations, including but not limited to:
- Telemarketing and SMS consent (TCPA and similar laws)
- Call recording and notification requirements
- Truth-in-advertising and trade licensing disclosures
Orvius provides tools; customers control how those tools are deployed on their lines. See SMS Terms for text-message program details.
4. Incident reporting
Report security concerns to hello@orvius.im. We investigate good-faith reports and will contact affected customers when required.
5. Subprocessors
The Service uses infrastructure and communications providers (cloud hosting, carriers, voice AI, payments). These vendors process data on our instructions under contractual safeguards.