Security & Trust Center
Engineered from the ground up with military-grade encryption, isolated tenant microservices, BTRC telecommunication compliance, and 24/7 Dhaka NOC telemetry monitoring.
Perimeter Defense & DDoS Mitigation
Multi-layered network filtering protecting API gateways from layer 3/4 and layer 7 volumetric attacks.
Automated WAF & Rate Limiting
Dynamic token-bucket rate limiting safeguards REST and SMPP endpoints against credential stuffing, brute-force OTP attempts, and volumetric spam floods.
Private SS7 Telco VPNs
All communication with mobile operator SMSC nodes (GP, Robi, Banglalink, Teletalk) travels across dedicated fiber IPsec VPN interconnects, entirely separated from the public internet.
Isolated Multi-Tenant Sandboxes
Client databases, virtual PBX instances, and custom application code run in isolated Docker containers with strict Linux cgroup and network namespace boundaries.
Data Cryptography: In Transit & At Rest
Zero unencrypted plain text across storage, backup archives, or network transit.
Encryption In Transit (TLS 1.3)
All incoming API calls, webhook dispatches, and dashboard interactions require TLS 1.3 with Perfect Forward Secrecy (PFS). Legacy SSL and TLS 1.0/1.1 protocols are completely disabled.
Encryption At Rest (AES-256)
NVMe SSD storage blocks, database transaction logs, and customer backups are encrypted using AES-256 encryption with automated encryption key rotation managed via hardware security modules (HSM).
Corporate Governance & Trust Resources
Review official contractual documents governing our platform operations: