Skip to main content
Setup

Security

How Chatley protects your account, your call recordings, and your API credentials — and the controls you are responsible for.

Security on a voice platform covers three things at once: your account, the call data your agents produce, and the credentials that reach your other systems. Some of it is ours to get right, some of it is yours.

Your account​

Passwords and sign-in. Use a unique password. If your team is larger than a couple of people, put everyone on their own login rather than sharing one — the team page covers adding members.

Workspaces are the boundary. Agents, knowledge, and call history belong to a workspace. Giving someone access to a workspace gives them the calls in it, so separate clients or business units into their own.

Review team access when someone leaves

Removing a person from your own systems does not remove them from Chatley. Revoke their access on the team page in the same pass.

API keys​

Your API keys act as your account. Treat them as secrets:

  • never commit one to a repository, and never paste one into a support ticket;
  • keep them server-side — a key in browser JavaScript is a public key;
  • rotate on a schedule, and immediately if you suspect exposure;
  • use separate keys per integration so one can be revoked without breaking the rest.
A leaked key can place calls

An API key can create agents and start outbound calls, which costs money and contacts real people. Revoke first and investigate second.

Call recordings and transcripts​

Recordings are personal data about the people your agents speak to, and often the most sensitive data in your account — callers volunteer things on a phone call they would never type into a form.

  • Decide who needs access to call history and scope workspaces accordingly.
  • Know your retention position and be able to state it — see Call recording & consent.
  • Obtain consent where the law requires it, and disclose that the caller is speaking to an AI.

The Privacy Policy covers data security and retention for account, billing and security data. It does not state a retention period for call recordings and transcripts, so set and enforce your own until it does.

Regulated data has its own positions: see HIPAA and PCI.

If you have data residency or zero-retention requirements, Enterprise accounts can be configured for them — contact security@chatley.ai.

Webhooks​

Webhooks push call and lead data to your systems. Anyone who can reach the endpoint can post to it unless you verify the request, so:

  • terminate webhooks over HTTPS only;
  • verify the payload before trusting it;
  • treat the receiving endpoint as internet-facing, because it is.

Reporting a vulnerability​

Report suspected vulnerabilities to security@chatley.ai. Please do not test against live customer traffic or place real calls as part of a test.

No published disclosure policy yet

Chatley does not currently publish a coordinated disclosure policy or a response-time commitment. Reports are still welcome at security@chatley.ai.