---
id: security
title: Security
slug: /security
description: How Chatley protects your account, your call recordings, and your API credentials — and the controls you are responsible for.
---

Security on a voice platform covers three things at once: your account, the call
data your agents produce, and the credentials that reach your other systems.
Some of it is ours to get right, some of it is yours.

## Your account

**Passwords and sign-in.** Use a unique password. If your team is larger than a
couple of people, put everyone on their own login rather than sharing one — the
[team](./admin/team.md) page covers adding members.

**Workspaces are the boundary.** Agents, knowledge, and call history belong to a
[workspace](./admin/workspaces.md). Giving someone access to a workspace gives
them the calls in it, so separate clients or business units into their own.

:::tip[Review team access when someone leaves]
Removing a person from your own systems does not remove them from Chatley.
Revoke their access on the [team](./admin/team.md) page in the same pass.
:::

## API keys

Your [API keys](./api/authentication.md) act as your account. Treat them as
secrets:

- never commit one to a repository, and never paste one into a support ticket;
- keep them server-side — a key in browser JavaScript is a public key;
- rotate on a schedule, and immediately if you suspect exposure;
- use separate keys per integration so one can be revoked without breaking the rest.

:::warning[A leaked key can place calls]
An API key can create agents and start outbound calls, which costs money and
contacts real people. Revoke first and investigate second.
:::

## Call recordings and transcripts

Recordings are personal data about the people your agents speak to, and often
the most sensitive data in your account — callers volunteer things on a phone
call they would never type into a form.

- Decide who needs access to call history and scope workspaces accordingly.
- Know your retention position and be able to state it — see
  [Call recording & consent](./legal/call-recording.md).
- Obtain consent where the law requires it, and disclose that the caller is
  speaking to an AI.

The [Privacy Policy](https://chatley.ai/privacy-policy) covers data security
and retention for account, billing and security data. It does **not** state a
retention period for call recordings and transcripts, so set and enforce your
own until it does.

Regulated data has its own positions: see
[HIPAA](https://chatley.ai/hipaa-compliance) and
[PCI](https://chatley.ai/pci-compliance).

If you have data residency or zero-retention requirements, Enterprise accounts
can be configured for them — contact security@chatley.ai.

## Webhooks

[Webhooks](./webhooks.md) push call and lead data to your systems. Anyone who
can reach the endpoint can post to it unless you verify the request, so:

- terminate webhooks over HTTPS only;
- verify the payload before trusting it;
- treat the receiving endpoint as internet-facing, because it is.

## Reporting a vulnerability

Report suspected vulnerabilities to security@chatley.ai. Please do not
test against live customer traffic or place real calls as part of a test.

:::note[No published disclosure policy yet]
Chatley does not currently publish a coordinated disclosure policy or a
response-time commitment. Reports are still welcome at security@chatley.ai.
:::

## Related

- [Legal & compliance overview](./legal/overview.md)
- [Data Processing Addendum](./legal/dpa.md)
- [Compliance](./compliance.md)
