Skip to content
Share one workflow. DRING calls in two minutes and qualifies the need. Get a call in two minutes
Get a call in 2 minutes See Agent Factory
Security

Six standards, each one tested

A voice agent adds new attack surfaces in the prompt, the output, the caller's identity and the actions it can take.

Six standards

Declared, then tested

Each line below names what is actually checked, not what sounds reassuring in a brochure.

  • Service continuityFailover is tested. When a component fails the call is closed in a controlled way, never dropped in silence.
  • Voice privacyVoice is masked at source, in the switchboard layer, before audio ever leaves the line. The masking is not reversible.
  • Prompt defenseInjection is tested. Attack scenarios are rerun regularly across different models, and every conversation passes an automatic security analysis.
  • Data protectionRecords are encrypted, and access to them is logged. Who read what is answerable after the fact.
  • Operator controlA single, tested stop. One defined step halts all automation, and that step is exercised rather than assumed.
  • Data residencyProcessing is locked to a region. Location, transfers and boundaries are documented and reviewed per deployment.

Data processing, consent, retention and access requirements are scoped for review in each deployment rather than treated as one blanket promise. Tenant isolation is enforced throughout: one customer's conversations never reach another customer's agent.

Least privilege by default

Every call reaches the agent through DRING Security first. Integrations start read-only, and a tool gains write access only with explicit sign-off.

Related: Quality and testing · Agent Factory · Line protection

Prompt defense

Prompt injection: how we test and how we block

A voice agent takes instructions from the person on the call by design. An attacker tries to turn that against it.

How an attack looks

A direct override: "ignore your instructions," mid-call.

Instructions hidden inside tool or web data: a CRM note, an order record or a webpage carrying text written for the agent, not the person reading it.

Staff impersonation: a caller claims to be an employee or the account holder to unlock actions meant only for a verified identity.

Refund or transaction pressure: a request outside policy, repeated or escalated, hoping persistence works where a direct ask would not.

What the agent does

Refuses out-of-scope instructions. Nothing said on the call changes its operating instructions.

Treats tool output as data, not commands. Instruction-like content coming back from a tool is ignored, not executed.

Verifies identity before privileged actions. An unverified claim is refused and logged for review.

Requires authorization for high-risk transactions. No refund, transfer or discount clears on request alone.

Offers a human handover instead of improvising an exception.

What an attack tries, and what stops it

AttackWhat the caller triesWhat stops it
OverrideIgnore your instructions, follow new rulesInstructions stay fixed all call, logged
Injected tool resultHides commands inside a CRM noteTool output is read, never executed
Spoofed identityClaims staff, supervisor or account holderChecked against verification, not the claim
Out-of-policy transactionPushes refund, transfer or discount repeatedlyNeeds explicit authorization, no exceptions
Data requestAsks to hear another customer's dataNot reachable; tenant isolation blocks it
Policy trapLeads toward an improvised promiseEvery reply checked against policy first

Every attempt is logged and reviewed.

How testing works

  1. Adversarial scenarios

    Overrides, injected content and traps, from a living library.

  2. Independent review

    Automated checks plus human review flag any disagreement.

  3. Output and transaction control

    Replies and high-risk actions are checked before release.

  4. Release scorecard

    Results sit beside quality metrics; nothing ships untested.

Defense in layers, not in the model. The protection does not rest on one model behaving well. It sits in several layers around the model, the attack scenarios are rerun regularly against different models, and every conversation passes an automatic security analysis afterward.

One regression suite. Every rule a customer gives us joins that agent's single regression suite. A new rule ships only when every existing rule still passes beside it, so a fix in one place cannot quietly break another.

  • Service continuity, failover tested
  • Voice privacy, masked at source
  • Prompt defense, injection tested
  • Data protection, encrypted
  • Operator control, manual override
  • Data residency, region locked
Carrier edge

Protection starts before the call reaches the agent

The same detect, stop and log logic guards the line itself. Repeated SIP attempts, spoofed caller IDs and robocall bursts stop at the carrier edge; verified callers pass.

What this means for your line

  • Carrier and PBX traffic reaches DRING only from an agreed IP allow list, with trunk credentials as a second check
  • Repeated failed registrations or malformed SIP requests can trigger an automatic block on the source, temporary for a first offense and permanent for a repeat one, so nobody can jam the inbound line
  • An unfamiliar number can be routed into a verification step, and a scheduled callback window can be honored where the workflow defines one
  • Repeated spam calls from the same number in a short window are blocked at the switchboard, so they never burn your package credit
  • Signaling and media are encrypted where the carrier and trunk support it, and every stop and every pass is logged

For the full telephony architecture, replicated SIP edge, media cluster, active and standby paths, see SIP trunks & carrier peering and line protection.

Data flow

How data flows

Data moves through a fixed, monitored path on every call, encrypted at every step.

Prompt injection Repeat dialing Flow escape Wrong info Data leak GUARDRAILS Speech-to-speech core Masked data Your systems Operator stopKill switch CALLER DRING AI STAFF Guardrails live Data masked Operator override TEST RELEASE MONITOR

Data is encrypted in transit with TLS 1.2 or higher and encrypted at rest. Tenant isolation, role-based access and automated monitoring apply across the pipeline.

Retention and rights

How long data is kept

Message content, call recordings, post-call analytics, account data and website analytics each carry a default retention period, followed by deletion or anonymization. The periods and the rules that override them by contract are set out in the privacy policy, which is the single source for them. Clients may request earlier deletion of any data type at any time.

DRING acts as a Meta WhatsApp Tech Provider and as a data processor on behalf of clients, who remain the data controllers. WhatsApp data is never used for advertising. For request paths, applicable rights and deployment-specific notices, write to [email protected] and review the privacy policy and the KVKK notice.

FAQ

Security questions

How do you use production conversations to improve an agent?+

With the data controls agreed for your operation, reviewed transcripts and outcome signals can improve that tenant's own agent, tests and release plan. Tenant isolation is enforced; customer conversations are not used to improve another customer's agent.

Can an integration write to our CRM without approval?+

No. Integrations start read-only, and any write action requires explicit sign-off per tool.

Where is our data processed?+

Processing and transfer arrangements are documented per deployment, with applicable safeguards reviewed as part of the security and privacy process.

Can we request deletion of our data early?+

Yes, clients may request earlier deletion of any data type at any time.

Can a caller trick the agent into ignoring its instructions?+

No. The agent's instructions and policy are fixed for the call and cannot be changed by anything a caller says. Every release is tested against instruction override, injected content and other prompt injection scenarios before it ships. See prompt defense for detail.

Browse the full FAQ

Scope your data and governance requirements

Walk through the data and governance requirements for your workflow. Send the form and DRING calls you in two minutes, says it is an AI and asks about your workflow.