Architecture
The platform is structured across separate application layers rather than as a single monolithic system. At a high level, this includes:- a backend API layer,
- a web dashboard layer,
- and a real-time voice processing layer.
Encryption
Data in transit should be encrypted using TLS across browser sessions, API traffic, and internal service communication. For cloud storage and database infrastructure, AWS documents encryption support for services such as S3 and RDS and positions AWS services for GDPR-compliant use when configured appropriately. Payment data is handled by Stripe rather than being stored directly on RapidCall infrastructure. (Amazon Web Services, Inc.)Authentication and workspace isolation
Authentication should be scoped at the workspace level so that access is limited to the environment a user is authorised to manage. Each workspace is designed to operate as a separate environment, with its own agents, phone numbers, call history, recordings, billing context, and team access. This matters especially for agencies and multi-client operators, because it reduces the risk of cross-workspace data exposure and keeps client environments operationally separated.Voice processing
RapidCall uses a real-time streaming architecture for live voice interactions. LiveKit positions its platform as real-time infrastructure for voice and multimodal applications, and its security materials state that LiveKit Cloud maintains SOC 2 Type II certification. Deepgram states that it has achieved SOC 2 Type I and Type II certification for its speech services. This is relevant because real-time call processing depends on low-latency streaming between telephony, speech recognition, model inference, and voice generation providers. (LiveKit)Third-party provider security
RapidCall relies on established infrastructure providers for core parts of the system. Their published security and compliance materials support the baseline security posture of the platform stack.
A few important provider-side notes:
- AWS publishes SOC reports, ISO/IEC 27001 certification information, and GDPR compliance resources. (Amazon Web Services, Inc.)
- Twilio publishes a security overview, GDPR information, and states that its SOC 2 Type II certification applies across its services. (Twilio)
- LiveKit states that LiveKit Cloud maintains SOC 2 Type II certification. (LiveKit)
- Deepgram states that it has SOC 2 Type I and Type II certification. (Deepgram)
Account security best practices
A few practical steps materially improve account security: Use strong, unique credentialsYour login protects access to agents, call records, contact data, and billing controls. Treat it accordingly. Use team roles instead of shared logins
Assign access through individual team accounts rather than sharing credentials. This improves accountability and makes it easier to revoke access cleanly. Rotate API keys periodically
If you use the API for custom workflows, rotate keys on a regular schedule and revoke any that are no longer needed. Review workspace access regularly
If you manage multiple workspaces, periodically confirm who still needs access to each one and remove stale access promptly.
