Security & architecture

The architecture, published.
No form, no badge wall.

We don't pretend to audit the server you run. We publish how the system works, what is encrypted and where, and what we can and cannot see. All of it on this page, with no form in front of it — the way an auditor would want it.

The core argument

Self-hosted: it runs inside the environment you already operate.

With self-hosting, call audio, recordings and call records stay on your server, so processing stays in the environment you already run. Hosted by us is different: Saj Serve operates that deployment. Account for that hosted service in your own data-processing review.

the self-hosted data path — every hop is yours
Per-leg encryption, stated exactly

What is encrypted, and where.

Browser and mobile calls are encrypted between the app and your server, with per-call keys that are never stored.

The admin console and everything between our own components runs encrypted in transit, with post-quantum-ready key exchange on the internal audio path.

Desk phones on your LAN carry audio on your own network, the same as every on-premise phone system ever sold. In a self-hosted deployment that traffic never touches the internet, and it can be encrypted end to end on request.

If a desk phone registers across the public internet, put it on your VPN or use the encrypted mobile and desktop apps. We say so in the docs, plainly.

Phones authenticate with the standard method every desk phone already speaks, and outbound calls carry a signed caller identity (STIR/SHAKEN) on carriers that support it.

What phones home

The complete outbound inventory.

Here is every outbound connection the system makes. That is the full list.

Media pathno phone-home
Call signallingyour network only
Licence validationa signed file on your box · no licence server to call home to
Automatic update daemonnone · updates are pulls you run
Crash or usage telemetry on callsnone
Hosted tierwe operate the box · export is documented

This is a topology you can check, not a policy you have to trust. Inspect the outbound traffic on the box and confirm the list yourself.

Key custody

Who holds which keys.

SIP credentialshashed per-realm, in your database
HTTPS certificatesissued and held on your server, or bring your own
Call encryption keyscreated per call, never stored
Recording encryptionAES-256, under a recording key that stays on your box and is shared with nothing else
Licence verificationdone locally by the software · no licence server
Customer isolationenforced in the database, so one tenant can never read another
Practices

What we do on our side.

Secrets fail closeda missing secret stops the system starting, rather than starting insecure
Emergency callingcannot be switched off by licensing
Exportconfig and data on every tier, including a lapsed licence
Database upgrades are append-only once releasedwe never rewrite history on your install
Every release is tested so one customer cannot reach another's dataautomated

This page provides the architecture, encryption details and outbound connection inventory. A hosted-service assurance report is not on this page.

Disclosure

Found something?

Report vulnerabilities to [email protected]. A human engineer reads that inbox. We acknowledge within two business days, keep you informed, and credit you if you want credit.

Please don't test against systems you don't own. That's what the free self-hosted tier is for.

Questions an auditor would ask? Ask them.