Security
How data, deliveries, accounts and infrastructure are protected, and how to report a vulnerability.
Delivery security
- Delivered files are never placed in public web directories.
- Downloads require authentication, ownership of the order, a delivered order status, an unexpired signed token and remaining download allowance.
- Every download attempt is logged and audited.
- Signed delivery links expire and have a finite download count; a fresh link must be issued by an administrator after that.
Account security
- Passwords are stored using a salted one-way hash and are never recoverable in plain text.
- Sessions use signed tokens with a fixed expiry.
- Administrative access is separate from customer accounts and is restricted to named individuals.
- Authentication endpoints are rate limited to slow credential-stuffing attempts.
Infrastructure
- Traffic is served over HTTPS; the application is intended to run behind a TLS-terminating reverse proxy.
- Supplier rate workbooks and source datasets are held outside the public web root and are excluded from version control.
- Uploaded supplier files are deleted immediately after they are parsed and staged.
- Database files and backups are held on encrypted volumes with restricted operating-system permissions.
What we do not hold
We do not store card numbers, bank credentials or cryptocurrency private keys. Payment is made directly from the customer's own wallet to a published address; we never take custody of customer funds and never ask for a seed phrase, private key or wallet password. Any message asking you for those is fraudulent and should be reported to us immediately.
Breach notification
If a security incident affects customer or personal data, we will investigate immediately, contain it, and notify affected customers without undue delay with what happened, what data was involved and what action to take. Where a notifiable personal-data breach occurs we will notify the competent supervisory authority within the statutory deadline, which is 72 hours under the GDPR.
Reporting a vulnerability
Report suspected vulnerabilities to support@callcenterboost.com. We will acknowledge within 3 business days. Please give us reasonable time to remediate before public disclosure, and do not access, modify or exfiltrate data belonging to other users while testing. We will not pursue legal action against researchers who follow this and act in good faith.
Related pages
- Trust Centre
- Company & Legal Information
- Data Sourcing & Lawful Basis
- Your Data Rights (Removal & Access)
- KYC, AML & Sanctions
- Sub-processors & Infrastructure
- Service Levels & Delivery
- Complaints & Escalation
- Data Processing Terms
Support is available through WhatsApp, Telegram and email. Payments are accepted in cryptocurrency only.