Security at Rundevou
This page describes the safeguards Loungest Limited applies to the Rundevou service. It is written for the people who evaluate suppliers, so it names components and protocols. It is not a certification and we do not claim one; it is an honest description of how the system is built today. The contractual commitments are in the Service Agreement and the Privacy Policy.
1. Who operates the service
Registered office: Initial Business Centre, Wilson Park, Manchester, M40 8WN, United Kingdom
Phone: +44 161 394 0791 · Email: [email protected] · Website: loungest.co.uk
The telephony servers, the AI bridge and the member portal are operated by Loungest Limited and hosted with providers in the European Union and the United Kingdom.
2. Voice in transit
- Public telephone network. A call from a Caller's phone to the number you forward to travels over the ordinary telephone network until it reaches our carrier. That leg is encrypted or not according to the carrier and the Caller's own network, as with any phone call.
- Carrier to our servers. SIP signalling between our carriers and our telephony servers uses TLS, and media uses SRTP, wherever the carrier supports it. We do not accept unencrypted signalling from the internet.
- Browser calling widget. WebRTC sessions use DTLS-SRTP for media and secure WebSockets (WSS) for signalling. The widget obtains a short-lived token from our servers, signed with a secret held only there; tokens expire after five minutes, are bound to the requesting address, and token issuance is rate-limited per address.
- To the AI. Audio is streamed from our telephony bridge to Google's Gemini API over an encrypted WebSocket (WSS, TLS 1.2 or higher). Google does not receive your Caller's telephone number as part of that stream.
3. Data at rest
- Recordings, transcripts and each tenant's receptionist configuration are stored as objects in Cloudflare R2, which encrypts every object at rest with AES-256. Objects are keyed by tenant and extension identifiers, and the application only ever reads a tenant's own prefix.
- Account data, bookings, orders, usage and the knowledge base live in the member portal's database, on servers in the European Union, on encrypted volumes, with backups held by the hosting provider.
- The ledger of checkout events on this website is a file outside the web root, readable only by the service user.
4. Tenant isolation
Every tenant has its own extension on the telephony side, its own configuration object in storage, and its own rows in the portal database. Team seats and hunt groups can only ever reference a tenant's own endpoints; the provisioning API rejects anything else. Dashboard and API requests are checked against the signed-in tenant on every call.
5. Payments
- Checkout happens on Stripe's and PayPal's own hosted pages. Card and wallet details never reach our servers, which keeps this site in the lightest PCI scope (SAQ-A).
- Prices are decided on our server from a fixed plan table; nothing the browser sends can change an amount.
- Webhooks from Stripe and PayPal are verified against their signatures before anything is recorded, and replayed events are discarded.
- The receptionist is designed never to take payment card numbers by voice. Callers pay at your premises, or you arrange payment with them after the call. The service does not send text messages or payment links to Callers.
6. Access control
- Staff access to production systems is by named accounts over SSH with keys, limited to the people who operate the platform.
- Staff do not listen to recordings or read transcripts except for support you have asked for, a security investigation, or a legal requirement.
- Secrets (API keys, webhook signing secrets, SMTP credentials) are held in files outside any web root with owner-only permissions, never in the website source and never in version control.
- Public endpoints on this site are rate-limited per client address, and the site sits behind Cloudflare's network, which absorbs volumetric attacks and filters abusive traffic.
7. Software and operations
- The platform runs on maintained releases of Linux, PHP, WordPress and Asterisk, with security updates applied as they are published.
- All input from Callers, Subscribers and gateways is validated server-side; output to pages is escaped; database access uses prepared statements.
- The code base is reviewed and audited on a rolling basis, and findings are fixed before features are added.
8. Incidents and breach notification
If we become aware of a security incident affecting personal data, we contain it, assess it, and, where the law requires, notify the Information Commissioner's Office within 72 hours and the affected Subscribers without undue delay, with enough detail for them to meet their own obligations to their Callers.
9. Reporting a vulnerability
If you believe you have found a security problem in Rundevou, email [email protected] with "Security report" in the subject. Please give us a reasonable time to fix it before disclosing it publicly, and do not access, modify or retain other people's data while testing. We will acknowledge your report, keep you informed, and credit you if you wish.
10. Sub-processors
The providers that handle personal data for us, and where, are listed in section 8 of the Privacy Policy. We give Subscribers notice before adding one.