Skip to content
Security & Privacy

Every call disclosed. Every recording accounted for.

COM8 Voice tells every caller they are speaking to an automated assistant, never takes card numbers by voice, and keeps recordings encrypted in the UAE with retention you control.

  • Every caller is told.

    Each call opens by disclosing that the caller is speaking to an automated assistant and that the call is recorded. It can't be switched off.

  • No card numbers by voice.

    The agent refuses card details and sends a secure payment link instead. Anything that looks like a card number is redacted from transcripts.

  • Your data never trains any model.

    Calls, transcripts and recordings are used to run your service. They are never used to train models.

  • Retention you control.

    Recordings and transcripts are deleted on the schedule you set, and data-subject requests are supported.

How a call travels — and where it stays

Calls reach COM8 Voice through licensed UAE carriers. Audio, transcripts and recordings are processed and stored in-region, encrypted in transit and at rest.

Your line

Your caller

Dials your existing number and hears the disclosure first.

Your line

Licensed UAE carrier

e& or du SIP trunk · your number, mapped to your business.

COM8 Voice · UAE

COM8 Voice agent

Speech and reasoning · tools call your systems · TLS 1.2+.

COM8 Voice · UAE

Dashboard & storage

UAE region · encrypted · tenant-isolated · audit logs.

Recordings and transcripts never leave the UAE region.

Defence in depth, layer by layer

COM8 Voice runs in a private environment with each tier isolated. Here is how it is put together.

  1. 01

    Telephony

    Numbers through licensed UAE carriers on SIP trunks. Signed webhooks only, with every call mapped to exactly one business.

  2. 02

    Application tier

    Containers in private subnets with no public IPs. Tool calls to your systems are typed, timed out and traced.

  3. 03

    Data tier

    Managed databases and recording storage encrypted at rest with customer-managed keys, isolated per business.

  4. 04

    Identity, secrets & audit

    Per-service roles with no long-lived keys, rotated secrets, and an audit log of every sign-in, change and recording playback.

  5. 05

    Region & compliance

    Hosted in the UAE (for example AWS me-central-1), designed around the UAE PDPL, with enterprise deployments in a dedicated account.

Access that follows your policy

  • Single sign-on & MFA

    OIDC or SAML with Microsoft Entra ID. MFA enforced, with session rules that follow your policy.

  • Role-based access

    Agents, managers, quality and IT each see only the branches, queues and screens their role needs.

  • Audited recordings

    Every recording playback and transcript export is logged with who, when and why.

  • Redaction by default

    Card and ID numbers are redacted from transcripts before anyone reads them.

Bring your IT team. We'll bring the architecture.

We walk your IT and legal teams through every component and complete your security questionnaire before a pilot starts.

Frequently asked questions

  • In the UAE, encrypted at rest and isolated per business. Retention is configurable, with automatic deletion.

  • Every call discloses automation and recording up front, numbers come through licensed UAE carriers, and data handling is designed around the UAE PDPL.

  • No. It refuses card numbers by voice and sends a secure payment link by SMS or WhatsApp, keeping calls out of card-data scope.

  • Yes. We run a security session with your IT and legal teams, walk through the data flows and complete your questionnaire before any pilot starts.

  • Point your number back at your own line. Calls stop reaching the agent immediately, and your data is deleted on request.