
We faced the information security issue, as the main part of our product. Below we habe listed all pssoible security weaknesses and what we have done to solve them.
Access to the system by Phone2B Technical Support
When installing the system, all passwords are delivered to the customer. From this moment, our technical support can only access the system if the remote assistance function is activated by the customer.
This function dynamically creates a User and password that can be used for only one connection. The reason to do that is to permit the client to know every time we have access to the system information.
Call recordsDetalhes sobre Gravação das Ligações
The Call Records feature runs a risk of unauthorized access to them. So, the system allows only the master user, special login which is delivered to the director or owner of the company, to record and listen to phone calls.
ReportsDetalhes sobre Relatórios
We believe that the call reports are nothing more than company`s telephone secrecy. An improper access to the calls list from the company`s business manager can be dangerous.
Therefore, only the Master User can authorize access to the report module. Not even the technical support staff will have access to this module.
Encrypted backup
The data system was encrypted and can only be read by Phone2B, in order to ensure that it will be not copied over the backup file.
Calls Record, without mentioning any information in the file name
The filename of the calls stored on the server is encrypted, so even there is the possibility of a direct access to the operating system, it will be not possible to identify the call trough the file name.
Event viewer
The main actions of the system will be logged by the Event Viewer. The purpose of this actions is to identify every change or request made by users, including the user master.