Security

Your calls. Your data. Protected.

Revafone is built on the same security primitives banks use. Encryption, audit logs, and Australian-hosted infrastructure — by default.

The basics, done right

Six pillars, no shortcuts.

Encrypted in transit & at rest

Every call, recording, and transcript is encrypted with AES-256 at rest and TLS 1.3 in transit.

Hosted in Australia

Your data stays on Australian soil, in tier-3 data centres with 99.99% uptime guarantees.

Least-privilege access

Internal staff access is role-gated and audit-logged. No engineer can read your transcripts without explicit approval.

Caller privacy by default

Recordings auto-delete after 90 days. Customers can request deletion at any time and we honour it within 7 days.

Compliance-ready

Aligned with the Australian Privacy Act and GDPR. SOC 2 Type II audit in progress.

Spam & abuse protection

Robocalls, telemarketers, and known-bad numbers are filtered before they reach you.

Trust

A shared-responsibility approach.

This page is maintained by Revafone to describe enabled platform controls and current practices. It is not a certification or audit attestation.

We are responsible for

Infrastructure security, encryption, network controls, vulnerability management, and incident response.

You are responsible for

Managing your account, choosing strong passwords, enabling MFA, and configuring who on your team has access.

Together we protect

Caller PII, recordings, transcripts, calendar data, and any custom data you push through integrations.

Report a vulnerability.

If you've found a security issue, please email security@revafone.com. We respond to every report within 24 hours.

Security shouldn't be a feature. It's the foundation.

Start free. Your data stays yours, always.