Security & Reliability

Keep your data protected with Chatti

Redundancy, Availability, and Uptime

Chatti is committed to supplying a highly available platform and we do our best to minimise outages. Through use of a content delivery network, geographically redundant data centres, and redundancy within each data centre, we ensure failovers exist at several levels to maximize uptime. 

Information about availability and outages can be found on our status page. We also take regular offsite backups of important data to ensure business continuity.

Security Testing

We support responsible disclosure of vulnerabilities and believe it strengthens the security of our services. We also conduct periodic audits of application security, and periodic third party testing to discover and address any identified vulnerabilities.

Physical Security

Our servers are hosted by IBM Softlayer and AWS in data centres in Europe, the United States, SE Asia and Australia. Softlayer provides us with hardware, network connectivity and secure physical space relating to our customer data. 

Softlayer is compliant with ISO 27001 and other standards, and security information about their data centres can be found here.

System Security

We use firewalls and logical access control to protect our servers from unauthorised system access, allowing only trusted operations personnel to manage our systems. 

We also make sure to use strong configuration standards to harden our servers, and we keep them up-to-date with the latest security patches.

Application Security

We support strong cryptography for communication over public networks, so that your Dashboard password, API secret, and contents of your communications may be protected in transit as set forth below.

TYPE OF
COMMUNICATION
SECURE
PROTOCOLS USED
OTHER PROTOCOLS USED
Between customers and Vonage API'sHTTPS, SMPP-over-SSL, SIPSSMPP, SIP, RTP
DashboardHTTPS-
Between Vonage and carriersHTTPS, SMPP-over-SSL, SIPS, SMPP-over-IPsecHTTP, SMPP, ENUM, SIP, RTP

Encryption

We still support unencrypted protocols on the customer side in response to customer demand, but we strongly encourage customers to use secure protocols. Rest assured, the security of your data is unaffected by the communications protocols used by Chatti’s other customers because of the logical segregation between customer accounts. 

In connection with the provision of our services, Chatti and its technology partners, Vonage, has secured direct relationships with telecommunications carriers and similar service providers around the globe. While many of our connections with these carriers are secure, some of these “last mile” connections are unencrypted. 

This is beyond our control and depends on the carrier, as some telecommunications providers have legacy infrastructure and do not currently support secure protocols. We opt for secured communication with carriers when available.

Account Management & Access

We have rate limiting in place on API calls and Dashboard logins to prevent brute force attacks. Password complexity requirements are enforced on API secret and the Dashboard password. Dashboard passwords are cryptographically hashed before storing in our database. The Dashboard supports 2-factor authentication when elected for customers who want to add an additional access control. 

If this is enabled, Dashboard logins require an additional verification code, which is sent by SMS or automated phone call to the phone registered on your account, to be entered when logging in from an IP address which differs from the one used on the previous successful login. 

On request, we can enable restrictions on a Dashboard account such that it can only be logged into from specified IP addresses.

Compliance and Assurance Programs

Our data centre vendor (AWS & IBM) are accredited with the following assurance programs/standards:

  • PCI DSS Level 1
  • SOC 1/ ISAE 3402
  • SOC 2
  • SOC 3
  • IRAP (Australia)
  • ISO 9001
  • ISO 27001
  • MTCS Tier 3 Certification
  • FERPA
  • ITAR
  • Section 508 / VPAT
  • FedRAMP (SM)
  • DIACAP and FISMA
  • NIST
  • CJIS
  • FIPS 140-2
  • DoD CSM Levels 1-2, 3-5
  • G-Cloud
  • IT – Grundschutz
  • MPAA
  • Cyber Essentials Plus
  • European Union Data Protection Directive 95/46/EC

Have a Question?

Our customer success team is here to help.

Security You Can Trust

24/7

Sale & Support

24B

Minutes & SMS
annually

100%

Australian
Direct Routes

100%

Satisfaction
Guaranteed