Security
Overview
RevDesk (operated by Cell Labs, Inc.) protects your data with industry-standard security measures and welcomes coordinated disclosure from the security research community. This page covers how we secure your data — encryption, access controls, and compliance posture — and how to report a vulnerability.
If you have discovered a security vulnerability in RevDesk, we encourage you to let us know right away. We welcome the opportunity to work with you to resolve the issue promptly, and you may submit reports anonymously.
Report a vulnerability
Submit your findings directly to our HackerOne inbox — anonymous reports are welcome. If you'd rather report by email, write to security@revdesk.com.
Report a vulnerability on HackerOneOur machine-readable contact details are published at /.well-known/security.txt.
Data encryption
We encrypt your data in transit and at rest so it stays protected from unauthorized access, disclosure, alteration, or destruction.
- In transit (TLS 1.3)
- All traffic between you, our services, and our telephony partners is encrypted in transit using TLS 1.3.
- At rest (AES-256)
- Call recordings, transcripts, and account data are encrypted at rest with AES-256.
- Encrypted backups
- Backups are automated and encrypted, with redundancy across our infrastructure provider's data centers.
- Payment data
- Card details are processed securely through Stripe — we never store credit card numbers.
Access controls
Access to customer data is tightly controlled and continuously monitored across our systems and our infrastructure providers.
- Authentication
- Multi-factor authentication is available on every account, with secure session handling throughout.
- Least-privilege access
- Role-based permissions enforce least-privilege access to customer data across our team.
- Infrastructure
- AWS data centers with physical security, redundancy, and automated encrypted backups.
- Network security
- Firewalls, intrusion detection, and DDoS protection guard our network perimeter.
- Security audits
- Regular third-party penetration testing and vulnerability assessments.
- Incident response
- Documented procedures for security incidents and data breaches, plus vendor security reviews of every third-party provider.
Compliance & certifications
HIPAA: RevDesk is HIPAA-compliant and signs Business Associate Agreements with healthcare customers on request. Our telephony (Telnyx), media (LiveKit), and STT (Deepgram) subprocessors all support BAAs.
SOC 2 Type II: We are actively pursuing SOC 2 Type II certification (audit in progress). All of our core subprocessors (Telnyx, LiveKit, Deepgram, Stripe, Neon) are already SOC 2 Type II certified.
GDPR: We handle personal data in line with the GDPR, including data-subject rights and data-processing commitments.
No security is perfect
While we implement strong security measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security. If you become aware of any security vulnerability, please report it to security@revdesk.com.
Program standards
Our disclosure program is covered by the following standards. Good-faith research conducted under them is authorized.
- Coordinated Vulnerability Disclosure
- We work with you to validate, remediate, and disclose issues on a coordinated timeline.
- Safe Harbor
- Good-faith research conducted under these guidelines is authorized. We will not pursue or support legal action against you for it.
- Open Scope
- Any asset RevDesk (Cell Labs, Inc.) owns or operates is in scope. Third-party services we don't host are out of scope.
- Core Ineligible Findings
- Reports with no real-world security impact (e.g., missing best-practice headers, theoretical issues with no PoC) are typically not actionable.