--- title: Security and compliance description: Product controls, customer responsibilities, and claims requiring contractual confirmation. --- ## Implemented controls documented here - KYC gates calling and campaign access. - Developer APIs use revocable `X-API-Key` credentials. - CRM webhooks require HTTPS and support HMAC-SHA256 signatures. - Widget sessions use allowed-origin controls and short-lived sessions. - Contact records support status, tags, notes, and `junk_dnc`. - Campaigns support timezone-aware calling windows. ## Customer responsibilities Before processing personal data or contacting a person, determine your lawful basis, consent and notice requirements, retention policy, opt-out process, DND/NCPR workflow, DLT/provider obligations, and any sector-specific rules. ## DPDP and data requests VaniAgent features can support data minimization by limiting imported fields and retention. The public Developer API does not currently document a right-to-erasure endpoint. Route access, correction, deletion, or retention requests through your approved support and account process. ## Data protection claims Do not assume a particular encryption cipher, TLS version, cloud region, recording bucket, or residency guarantee from this guide. Obtain the current security architecture, data-processing terms, subprocessors, retention commitments, and contractual residency commitments from VaniAgent before an enterprise security review. This page provides operational guidance and is not legal advice.