VoIP security for your business calls
A phone system carries customer conversations, voicemails and recordings, so it needs the same care as any other business system. This page explains how Youvoip protects calls in transit and data at rest, who can see what, how toll fraud is kept out, and how emergency addresses and recording consent are handled.
Encrypted VoIP calls: TLS for signalling and SRTP for media
Calls placed through the Youvoip apps, the web softphone and supported SIP desk phones are encrypted in transit. Call signalling, the part that sets up and ends the call, travels over TLS. The voice itself travels as SRTP, so the audio is encrypted between the device and our platform. Once a call leaves our network for the public phone network to reach a landline or a mobile on another carrier, it is carried under that network's own rules, as with any phone call.
- TLS for call signalling
- SRTP for call audio
- Encrypted connections for the apps, the web softphone and the admin console
Call recordings and voicemails encrypted at rest
Call recording files, voicemails and their transcripts are encrypted at rest. Access to them follows the permissions you set, and downloads and exports are recorded. Your call recordings stay yours: you can export them and delete them, and when a retention period ends they are removed.
- Recordings, voicemails and transcripts encrypted at rest
- Access limited by role and team
- Export and deletion under your control
Access controls and admin roles
Every person signs in with their own account, and each account has a role. Users see their own calls, voicemails and recordings. Supervisors see the teams they manage. Admins manage numbers, call flows and users. On Ultimate, multi-site setups add site-level admins who manage one office without seeing the others. On Enterprise, custom admin roles let you define exactly which permission belongs to whom.
- Individual accounts, no shared logins
- Roles for users, supervisors and admins
- Site-level admins on Ultimate
- Custom admin roles on Enterprise
SSO, audit log and retention policies on Enterprise
Enterprise VoIP systems connect to your identity provider with single sign-on over SAML, including Okta and Microsoft Entra ID, and SCIM removes access when someone leaves your directory. The audit log records admin actions such as changes to call flows, new numbers, role changes and recording exports. Data retention policies decide how long recordings, voicemails and call detail records are kept.
Toll fraud protection with international calling restrictions per user
Toll fraud happens when someone uses a stolen login or an open phone line to place expensive international calls. Youvoip lets admins restrict international calling per user: allow it only for the people who need it, and keep it off for everyone else. Combined with individual logins and roles, this limits what a compromised account can do.
- International calling on or off per user
- Individual credentials for every app and desk phone
- Admin changes visible in the audit log on Enterprise
E911 addresses for every user
Each user has a registered emergency address. When someone dials 911, that address goes with the call so emergency services know where to go. Because VoIP works wherever there is internet, people who move offices or work from home need to keep that address current, and admins can see and update the addresses for their team. VoIP 911 also depends on a working internet connection and power at the device.
Recording consent announcements
Laws about recording calls differ by state and country, and some require every party to agree. Youvoip can play a recording announcement at the start of recorded calls, so callers hear that the call may be recorded before the conversation begins. You decide which numbers, queues or users record calls, and the announcement follows those settings.
Security review documents
Enterprise customers who run a vendor review can request security review documents. Write to [email protected] with your questionnaire and the name of the reviewer, and we send what your process needs.
VoIP security questions
Are Youvoip calls encrypted?
Yes. Signalling travels over TLS and the call audio over SRTP between your apps or supported desk phones and our platform. Recordings and voicemails are encrypted at rest.
How do you prevent toll fraud?
Admins can restrict international calling per user, every person has an individual login, and on Enterprise admin actions are recorded in the audit log.
Who can listen to our call recordings?
Only people whose role allows it: the user on the call, supervisors of that team and admins you choose. On Enterprise you can define custom roles.
Can callers be told that a call is recorded?
Yes. A recording announcement can play at the start of recorded calls, following the recording settings you choose.
A phone system with security built into every plan
Encrypted calls, roles and fraud controls come with every account, and Enterprise adds SSO, the audit log and retention policies. See how it fits your team on the business VoIP features page or check the VoIP pricing.