INSIDE THE CUSTOMER NETWORK
Access only to the voice systems it serves.
The recorder communicates with the relevant Cisco voice nodes for signaling and media. It does not introduce a separate local administration stack.
Security architecture
The recorder uses a narrowly defined path: internal access to the Cisco voice infrastructure and outbound HTTPS to call-recording.com.
Cisco Voice
customer network
Recorder
headless runtime
call-recording.com
outbound HTTPS
every hop the recorder initiates — nothing inbound
INSIDE THE CUSTOMER NETWORK
The recorder communicates with the relevant Cisco voice nodes for signaling and media. It does not introduce a separate local administration stack.
outbound to call-recording.com
Control communication, CDR delivery, and recording uploads use outbound HTTPS to the call-recording.com SaaS backend.
ALIGNED WITH ZTNA PRINCIPLES
The recorder does not accept internet-originated management connections. There is nothing to publish, proxy, or expose — it initiates every connection itself.
Administration remains centralized in the SaaS platform. A headless runtime means no local web surface to patch, protect, or audit.
Recording uploads are protected in transit. Once stored, call recording audio files and their associated metadata are encrypted at rest using AES-256. Encryption is applied automatically throughout the storage layer, supporting common encryption-at-rest control requirements while access remains authenticated and scoped to your organization.
The whole review. Most recording platforms need a meeting for this.
FOR THE FIREWALL CHANGE REQUEST
HTTPS and secure WebSocket outbound on TCP 443, AXL SOAP, SIP/SIPREC, and forked RTP inside the voice network — nothing inbound from the internet. Attach the PDF or Visio file directly to your security review.
SECURITY ARCHITECTURE
Deploy a recorder and validate the required Cisco voice and outbound HTTPS paths.