Products & Services

Security architecture

Low-footprint network access for modern security models.

The recorder uses a narrowly defined path: internal access to the Cisco voice infrastructure and outbound HTTPS to call-recording.com.

Cisco Voice

customer network

Recorder

headless runtime

call-recording.com

outbound HTTPS

every hop the recorder initiates — nothing inbound

INSIDE THE CUSTOMER NETWORK

Access only to the voice systems it serves.

The recorder communicates with the relevant Cisco voice nodes for signaling and media. It does not introduce a separate local administration stack.

outbound to call-recording.com

A single encrypted management and delivery path.

Control communication, CDR delivery, and recording uploads use outbound HTTPS to the call-recording.com SaaS backend.

ALIGNED WITH ZTNA PRINCIPLES

Reduce exposed services and trust only the required paths.

No inbound internet access

The recorder does not accept internet-originated management connections. There is nothing to publish, proxy, or expose — it initiates every connection itself.

No local management portal

Administration remains centralized in the SaaS platform. A headless runtime means no local web surface to patch, protect, or audit.

AES-256 encryption at rest

Recording uploads are protected in transit. Once stored, call recording audio files and their associated metadata are encrypted at rest using AES-256. Encryption is applied automatically throughout the storage layer, supporting common encryption-at-rest control requirements while access remains authenticated and scoped to your organization.

attack-surface audit — recorder
inbound internet ports open 0
management portals exposed 0
UDP ranges required 0
port-forwarding rules 0
outbound TLS paths 1

The whole review. Most recording platforms need a meeting for this.

FOR THE FIREWALL CHANGE REQUEST

Every protocol, port, and direction on one page.

HTTPS and secure WebSocket outbound on TCP 443, AXL SOAP, SIP/SIPREC, and forked RTP inside the voice network — nothing inbound from the internet. Attach the PDF or Visio file directly to your security review.

Solution topology — technical view with protocol flows open full size
call-recording.com technical topology: recorder appliances in the customer recording tier connect outbound-only over TCP 443 to the call-recording.com cloud, use AXL SOAP and SIP/SIPREC with the Cisco Unified CM cluster, and receive forked RTP media from phones with Built-in Bridge.
Take it to your review — PDF Visio (.vsdx) SVG

SECURITY ARCHITECTURE

Review the network model in your own environment.

Deploy a recorder and validate the required Cisco voice and outbound HTTPS paths.

Begin a Secure Trial