Security
Security practices
Last updated: 28 August 2026.
Reporting
Report suspected vulnerabilities to karim@engilane.com. Include steps to reproduce and impact. We do not operate a paid bug bounty or formal certification program.
Machine-readable contact: security.txt.
Authentication
Passwordless email codes via Brevo. Session tokens are random, stored hashed with a server pepper, and carried in an HttpOnly, Secure, SameSite=Lax cookie. Mutating API routes require a matching Origin header.
Webhooks
Each agent has a unique bearer secret shown once at creation. We store only a peppered hash. Webhook bodies are size-limited and rate-limited per IP.
Tenancy
Organization id is enforced on agents, rubrics, calls, evaluations, and retention deletes. Cross-tenant access by id guessing is rejected at the database query layer.
Billing
Licence keys are verified with Gumroad over TLS. Only a peppered hash and plan metadata are persisted. Billing attach and workspace wipe require the owner role.
What we do not claim
CallProof is not SOC 2, ISO 27001, or PCI certified. Card data never touches our infrastructure because Gumroad handles checkout.