Security
TelEcho is an AI voice agent platform built and operated by RTC LEAGUE, Inc. This page details the technical and organizational measures we apply to protect call audio, transcripts, chat/WhatsApp content, and account data processed through the platform. For RTC LEAGUE's corporate-level security program, see the RTC LEAGUE Security & Trust Center.
Last Updated: 20 Jul 2026Encryption
- In transit: TLS 1.2 or higher for all data moving between the client, the TelEcho API, telephony carriers, and downstream AI providers
- At rest: AES-256 for call recordings, transcripts, chat/WhatsApp message content, workflow configuration, and application databases
Identity & Access Control
- Role-based access control (RBAC) enforced on a least-privilege basis for internal systems that touch Customer Data
- Single sign-on (SSO) and multi-factor authentication (MFA) available for Enterprise-tier Customer accounts, and enforced internally for administrative access to production systems
Network & Infrastructure Security
- Segmented production environments, isolating the telephony routing layer, application layer, and data stores from each other
- Perimeter defense via firewall and web application firewall (WAF)
- Private networking for backend service-to-service communication
- Centralized logging and intrusion detection across the API, telephony, and application layers, with audit trails for any access to Customer Data
Vulnerability Management
- Periodic vulnerability scanning of production infrastructure
- Recurring third-party penetration testing (cadence confirmed to prospective Enterprise Customers under NDA)
Business Continuity & Disaster Recovery
- Encrypted, redundant backups across availability zones for the cloud region selected by the Customer
- Documented incident-response and disaster-recovery procedures with defined roles and escalation paths
- Recovery Time Objective (RTO) and Recovery Point Objective (RPO) figures available to Enterprise Customers under NDA
Personnel Security
- Confidentiality agreements and security-awareness training required for all personnel with access to Customer Data
- Background checks conducted where legally permitted
- Access to production systems is provisioned least-privilege and reviewed periodically
Telephony & Voice Architecture
TelEcho routes voice traffic through PSTN/SIP-trunked telephony carriers (see Sub-processors below) for call origination and termination. Call setup, routing, and disposition are measured against the uptime commitments in Section 1 of our Service Level Agreement. Voice response latency for the Ultra Low Latency tier is measured end-to-end, from end-of-speech detection to first audio byte returned, with a median target under 500 milliseconds.
AI/ML Data Flow & Model Providers
Inbound audio is processed through a speech-to-text (STT) provider to produce a transcript, the transcript and call context are passed to a large language model (LLM) provider for reasoning and response generation, and the generated response text is passed to a text-to-speech (TTS) provider to produce outbound audio. Each of these providers is a named Sub-processor (see table below). Where the provider offers a data-training opt-out at the API level, we configure that opt-out so Customer-submitted audio, transcripts, and workflow context are not used to train the provider's general-purpose models. TelEcho does not use identifiable Customer content to train its own proprietary models unless explicitly agreed with the Customer.
Call Recording, Consent & Regulatory Compliance
- Recording consent: Where TelEcho records or transcribes a call, the Customer, not TelEcho, is responsible for providing legally required notice and obtaining any required consent under applicable recording-consent, wiretapping, and data protection laws
- TCPA: Customers deploying outbound or automated calling/messaging are responsible for compliance with the U.S. Telephone Consumer Protection Act and equivalent Do-Not-Call regulations in other jurisdictions
- PHI: Customers may not submit protected health information unless a signed Business Associate Agreement (BAA) is in place and the HIPAA-eligible configuration is enabled
- PCI: Customers may not transmit unmasked payment card numbers through voice or chat transcripts outside of an approved, tokenized workflow
See our Terms of Service Section 2.2 and Privacy Policy Section 10 for the contractual language behind these obligations.
Sub-processors
TelEcho engages the following Sub-processors to provide the Service. RTC LEAGUE provides at least fourteen (14) days' notice of any new Sub-processor via this page or by email before that Sub-processor processes Customer Data.
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
| Twilio | Telephony / PSTN connectivity | Call audio, phone numbers, call metadata | United States |
| Telnyx | Telephony / SIP trunking (alternative route) | Call audio, phone numbers, call metadata | United States |
| SignalWire | Telephony / SIP trunking (alternative route) | Call audio, phone numbers, call metadata | United States |
| Deepgram | Speech-to-text transcription | Call audio, transcribed text | United States |
| AssemblyAI | Speech-to-text transcription (alternative route) | Call audio, transcribed text | United States |
| ElevenLabs | AI voice generation (text-to-speech) | Text of agent responses, generated audio | United States / EU |
| Cartesia | AI voice generation (alternative route) | Text of agent responses, generated audio | United States |
| OpenAI | LLM reasoning and response generation | Call transcripts, workflow context | United States |
| Cloud Infrastructure Provider (e.g., AWS) | Hosting, storage, compute | All Customer Data in transit/at rest on the platform | Region selected by Customer |
Compliance
| Framework | Status |
|---|---|
| SOC 2 Type II | Attained. Report available to Enterprise Customers under NDA |
| HIPAA (as a Business Associate) | Available via signed BAA, applicable only to workflows you designate as involving PHI |
| GDPR / UK GDPR | Data Processing Agreement available; Standard Contractual Clauses (SCCs) used for international transfers from the EEA, UK, or Switzerland |
| CCPA / CPRA | Addressed in our Privacy Policy; TelEcho does not sell Personal Information |
Uptime, Latency & Support
| Service | Monthly Uptime Commitment | Measurement |
|---|---|---|
| Voice Agent API & Telephony Routing | 99.9% | Successful call setup / total call attempts, excluding Scheduled Maintenance and Excluded Events |
| Chat / WhatsApp / WeChat Channels | 99.5% | Successful message delivery / total attempts |
- Voice response latency: median end-to-end latency under 500ms for the Ultra Low Latency tier, from end-of-speech detection to first audio byte returned
- Concurrency: guaranteed concurrent call capacity per your Order Form (e.g., 50+ concurrent calls), with additional capacity available on request
| Severity | Definition | Initial Response (Enterprise) |
|---|---|---|
| Sev-1 (Critical) | Complete outage of call handling in production | 1 hour, 24/7 |
| Sev-2 (High) | Major feature degraded, no workaround available | 4 business hours |
| Sev-3 (Medium) | Minor issue with an available workaround | 1 business day |
| Sev-4 (Low) | General questions, feature requests | 2 business days |
Build and Pay-as-you-go tiers receive commercially reasonable efforts but are not covered by SLA service credits unless otherwise agreed in writing.
Enterprise Documentation
Available under NDA to Enterprise Customers, contact your account representative or email info@telecho.io:
- Master Services Agreement (MSA)
- Data Processing Agreement (DPA)
- Service Level Agreement (SLA)
- SOC 2 Type II report
- Business Associate Agreement (BAA), for customers processing PHI
- Completed Vendor Risk Questionnaire (SIG Lite / CAIQ)