Legal

Information Security Policy

Where and how we keep your data; who accesses it and how.

Infrastructure

  • PBX and panel servers are hosted in Turkey; call recordings, conversation transcripts and reports do not leave the country. AI models process audio/text only at the time of the conversation; the Provider does not use this data to train models.
  • The PBX and panel are on separate machines and communicate over a private network; access to management interfaces is restricted by IP.
  • All web traffic is encrypted with TLS; WebRTC audio is carried with DTLS-SRTP.

Access management

  • Customer data is separated per customer; every query is limited to the customer identity in the session.
  • Role-based permissions in the panel (authorized / staff), visibility by page and extension, allowed IP list, foreign-IP blocking.
  • 2-step verification (Authenticator, email, SMS) and passkey (passkey/WebAuthn) are supported; a login lock (5 errors in 15 min per email) is applied.
  • Session cookies are HttpOnly, Secure, SameSite; 2 hours of inactivity / 12 hours absolute lifetime.

Storage of secrets

  • Passwords are stored with a one-way hash (bcrypt). API keys and integration secrets are encrypted with AES-256-GCM; the key is kept in the server configuration, not in the database.
  • Card details never enter Buluthat systems at any stage; they are processed on the payment institution's (iyzico, PayTR) pages. A saved card is represented only as a token. During the card keypress step on the phone, call recording is muted and keys are not logged.
  • Voice verification codes are stored only as hashes.

Recording and retention

  • Call recordings are kept for the standard 12 months; the customer downloads or deletes them from the panel at any time.
  • Activity history (logins, page views, setting changes) is kept for 180 days and visible in the customer panel.
  • Daily backups are taken encrypted and kept for 30 days in a separate location.

Incident management

  • System health (PBX sync, assistant service, email queue) is monitored continuously; the customer sees the system status in the Support Center.
  • In case of a suspected security breach, affected customers are notified within 72 hours; notifications under KVKK are made within the legal time limit.
  • To report a vulnerability: destek@buluthat.com (konu: "güvenlik").

Third parties

To the extent required by the Service, data is shared with telecommunications operators, payment institutions, voice/language model providers (OpenAI, Google) and email/SMS providers; data processing terms with each are set by contract.

Last updated: September 2026.