How a call flows
A caller rings the business. The business's phone system (PBX) or phone carrier sends the call to Vorelai's SIP server (Asterisk) over a trunk that belongs to that business alone. Asterisk hands the call's audio to Vorelai's media gateway on the same server, which streams it to Google's Gemini API and plays the agent's voice back. When the call ends, the gateway writes its record (transcript, summary, figures) to the database, and the business sees it in its dashboard.
Encryption
| Where | How |
|---|---|
| Phone system → Vorelai | SIP over TLS 1.2 or 1.3 on port 5061, with SRTP audio, for every trunk that turns it on. A trunk can require it: calls that aren't encrypted both ways are refused and sent to the business's fallback. Each call's record says how it was carried. Plain SIP and RTP on port 5060 also work, for phone systems that can't encrypt |
| Vorelai → Google | TLS (secure WebSockets and HTTPS) |
| Servers → database, dashboard → database | TLS (HTTPS, and Postgres with SSL required) |
| Database and file storage at rest | Encrypted by Supabase (AES-256) |
| Secrets a business gives us (its Gemini API key, its tools' API keys, calendar keys and tokens) | Stored in Supabase Vault, encrypted, readable only by the server functions that need them; never shown again after they're saved |
| Trunk passwords | Stored only as the SIP digest hash, shown once when made |
Who can see what
- Each business sees only its own data. Every table holding customer data has row-level security in the database: a dashboard user reads and changes only the workspaces they're a member of. Owners and admins manage settings; members read.
- Vorelai's servers use a service key that never leaves them. The SIP server has no database login: it gets its trunks from the media gateway on the same server, signed with a shared secret.
- Vorelai's staff. A short list of named people (platform admins, added by hand) can open the debug console and watch a call in progress, to diagnose a problem. Every watch is logged with who, which call and when. Staff don't otherwise read call content without the business's permission.
- Tests run against this. The automated tests check what each role can read and change, for every table, on every change.
The servers
- The call servers run Linux in Docker, in Frankfurt, Germany. Only SIP (5060, 5061), the call audio ports and SSH are open to the internet; the gateway's own ports listen on the server's loopback only, and the gateway accepts a call only when the SIP server signs for it.
- Asterisk loads only the modules the service uses (51, of about 325), so dialplan shell access, AGI and the management interfaces are absent.
- fail2ban bans addresses that keep failing SIP logins, for longer each time they return.
- Trunks can only reach the AI agent: nothing a trunk can do places a call out through Vorelai, so stolen trunk credentials can't run up phone bills.
- Production logs never hold what callers said, pressed or their numbers. The SIP server's security log, which records login attempts, holds callers' numbers for 3 days at most.
- Certificates come from Let's Encrypt and renew themselves.
Keeping the service up
- A call the agent can't take or keep (Vorelai busy, the AI failing, a plan's limit) goes back to the business's own phone system, to a fallback number it sets, so callers aren't left with silence.
- Servers stop gracefully: a restart takes no new calls and waits for calls in progress to end.
- Calls keep coming in while the database is unreachable: the SIP server keeps its copy of the trunks, the gateway keeps routing the numbers it knows, and a call record the database can't take is kept on the server's disk and written once the database is back (for 7 days at most).
- Monitoring watches calls, reply times, the AI's failures and the servers, and alerts Vorelai's team.
- The database runs on Supabase, which takes daily backups on its paid plans. Vorelai moves to one before it takes its first paying customer.
Development
- Every change runs automated tests before release: the database's permissions, real SIP calls through the whole system (encrypted calls included), the gateway and the dashboard, and a check of dependencies for known vulnerabilities.
- Secrets live in environment files on the servers and in Supabase, never in the code.
Incidents
If Vorelai confirms a breach of personal data it processes for a business, it tells the business's owners without undue delay, and within 48 hours of confirming it, with what is known: what happened, which data and roughly how many callers, what Vorelai has done, and whom to contact. The business makes its own notifications to authorities and callers; Vorelai gives it the information they need and answers its questions (DPA, section 5).
People
Everyone at Vorelai with access to customer data is bound to confidentiality, and loses that access promptly once they no longer need it.