Capability is granted. Authority is governed.
Cloudial treats security as part of the control plane's structure. The most important boundary is the one between what AI may interpret and what the platform may execute.
The security model
Tenant isolation
Data, numbers, routing, recordings and AI configuration are separated per tenant as a structural property of the platform.
Fraud controls
Destination policy, spend ceilings and anomaly detection are applied to outbound traffic per tenant.
Role-based permissions
Administrative scopes are granular and delegable across provider, reseller and customer tiers.
Audit trail
Every configuration change records the request, the interpretation, the approver and the applied result.
Encryption
Encrypted transport and storage across signalling, media handling and platform data.
Policy boundaries
Models hold no execution rights. Permitted operations are defined by policy, not by prompt.
Approval gates
Sensitive changes require explicit human approval before the platform applies them.
Scoped credentials
API keys and integrations carry explicit scopes bounded to a single tenant.
Grounded diagnostics
Operational answers cite SIP, CDR and telemetry records so conclusions can be verified.
Interpretation and execution are never the same step
This is the sequence every AI-initiated change follows. There is no path that skips it.
- 1
Request
Someone describes the change in plain language.
- 2
AI interpretation
Intent is mapped to concrete telecom objects.
- 3
Policy validation
Permissions, tenancy and guardrails are checked.
- 4
Configuration diff
A reviewable before/after is produced.
- 5
Deterministic execution
Approved changes are applied by the platform, not the model.
- 6
Audit trail
Who asked, what was approved, what changed.
Cloudial makes no certification claims on this page. Where formal attestations apply, they will be published once they have been completed and can be evidenced.
Boundaries for audio and acoustic analysis
Cloudial can derive acoustic and prosodic interaction signals from permitted audio. How those signals may be described and used is bounded deliberately.
Consent comes first
Recording, transcription and analysis are governed by explicit consent and per-tenant policy, including announcements and channel-level exclusions.
Signals are described honestly
We use terms such as acoustic and prosodic interaction signals, conversation escalation indicators and baseline-relative speaking-pattern changes — never 'emotion detection'.
Never the sole basis for high-impact decisions
Probabilistic interaction indicators must not be used alone to determine employment, disciplinary, credit, eligibility or similar outcomes.
No diagnostic claims
Cloudial does not represent these signals as medical, psychological, deception or definitive emotional diagnoses, and does not publish accuracy figures that have not been established.
Scoped permissions and retention
Access to audio, transcripts and derived signals is role-scoped, with configurable retention and deletion per tenant and per data class.
Human review for escalation
Escalation signals surface as recommendations to supervisors. Any resulting routing change follows the same policy validation and audit path as every other change.
Interaction signals are probabilistic indicators of conversation state. They are not medical, psychological, deception or definitive emotional diagnoses, and Cloudial does not publish accuracy figures for capabilities that are still in development.
Review the security model with our team.
We're happy to go through tenancy, permissions and audit in detail.