Skip to content

Security and Trust

How Hetaf protects your data: where it is hosted, encryption, data separation, access control, and responsible disclosure.

Last updated:

Contents

Businesses trust us with their customers' conversations, and we take that seriously. This page describes how we protect data in general terms; more detail is available to enterprise customers under the data processing agreement.

1Hosting

Our primary systems, database and recording storage run on Microsoft Azure in the United Arab Emirates (the UAE North region, in Dubai). This means data is stored outside the Kingdom; the basis for this transfer is explained in the privacy policy.

2Encryption

  • Data is encrypted in transit between your browser or app and our services.
  • The database and recording storage are encrypted at rest.
  • Credentials you add to connect your tools get an extra layer of encryption and are not shown again after saving.
  • We never see or store card numbers; they are entered on a licensed payment provider's pages.

3Data separation and access control

  • Each business's data is kept separate from others, and this is checked on every request.
  • Role-based permissions inside your team: only owners and admins manage billing and API keys.
  • API keys have limited scopes and cannot be used to move money or manage billing.
  • Our team's access to customer data is limited to those who need it to provide the service or support, and sensitive actions are logged.
  • A security check on sign-in and registration forms protects them from automated abuse.

4Private by default

  • Call recording on your numbers is off by default; when you turn it on, recordings are deleted automatically after 30 days.
  • Contact memory is off by default for every agent.
  • A do-not-call list and daily and monthly spending limits are available on every account.
  • No analytics, advertising or tracking tools on our website.

5Operations and continuity

  • We monitor our systems continuously and respond to incidents under documented procedures.
  • Code changes are reviewed and tested automatically before release.
  • The database is backed up regularly.
  • Service providers are bound by written confidentiality and security obligations.

We notify the authorities and affected people of data breaches as set out in the privacy policy.

6Responsible disclosure

If you find a security issue in Hetaf, report it to support@hetaf.ai with the steps to reproduce it and its likely impact. We ask you to:

  • Not access, change or keep other people's data, and stop and tell us as soon as you reach any data that is not yours.
  • Not disrupt or overload the service, and not run denial-of-service, social engineering or physical tests.
  • Give us reasonable time to fix the issue before any public disclosure.

We acknowledge every report, keep you updated on our progress, and appreciate reports made in good faith.

7Contact

This document is published in Arabic and English. If the two versions differ, the Arabic version governs.

Contact: support@hetaf.ai · karan@hetaf.ai