Security
Secure Dialer uses layered controls across the iPhone app, Cloudflare service, and the dedicated credentials created in your Twilio account. No service is perfectly secure.
Transport and storage
Secure Dialer uses HTTPS/TLS in transit. Dedicated Twilio API-key secrets, message bodies, and voicemail transcripts are encrypted at rest using AES-256-GCM with fresh nonces and a separately managed service secret.
Your Twilio master credential
The Twilio master Auth Token is sent directly from the iPhone to Twilio during setup, cleared from application state, and not sent to or persisted by the Provider backend. Never send your master Auth Token to support.
Device and credential controls
- Device-only iOS Keychain storage for sensitive local values.
- Per-device installation tokens and Apple App Attest verification for protected production actions.
- Device inventory, secure recovery, and revocation controls.
- Dedicated, independently revocable Twilio API keys and 90-day connection renewal.
- Hashed bearer tokens, callback secrets, invite codes, and recovery codes.
- Secrets excluded from support bundles.
Application and webhook controls
Application controls include strict request-size and content-type validation, E.164 number validation, ownership checks for selected caller IDs, rate limits, no-store responses, privacy-safe errors, and restricted deep links and App Intents.
Webhook controls use high-entropy capability URLs, account and resource matching, authoritative Twilio resource verification, strict body limits, and rate limits. Because the design does not retain the customer's master Auth Token, it does not use master-token-based Twilio signature validation. This compensating-control design requires independent review before broad launch.
Retention and deletion
Messages, voicemail database records, and actionable call diagnostics are deleted after 30 days; transient counters after two days. Voicemail audio remains hosted by Twilio and is streamed on authenticated request rather than persistently stored by Provider.
Secure disconnect removes Provider connection data and attempts to remove created Twilio resources and revoke the dedicated key. Individual message conversations and voicemails support deletion; Twilio-side records remain subject to your Twilio settings and actions.
Assurance status
Before unrelated external customers, the release plan requires independent security review and penetration testing, dependency, SAST, and secret scanning, operational log sampling, incident exercise, alert testing, and a formal decision on customer isolation and webhook controls. Completion of those external assurance gates is not represented here.
Report a security concern
Submit a concise description, affected feature, reproduction steps, and your preferred contact information through the contact form at https://www.gtm-solutions.ai/contact. Do not include passwords, Twilio Auth Tokens, private keys, message content, or other unnecessary personal data. Do not perform security testing without written authorization.
Questions, support requests, legal notices, privacy requests, and security reports:
Use the contact form →