Security
Apply communications controls within your security architecture.
Thirdlane provides identity, administrative, credential, signaling, media, retention, and activity-history controls. Their effectiveness depends on deployment design, endpoint support, identity-provider policy, storage configuration, and day-to-day operation.
Identity & access
SSO and directory sync against the identity systems you already operate.
OIDC single sign-on
Configure supported named providers or another OpenID Connect provider for administrator and Connect sign-in.
Identity-provider MFA
Apply multi-factor authentication through the configured identity provider and its access policies.
Directory synchronization
Synchronize users from Microsoft, Okta, or LDAP with configurable mapping and connection testing.
Role-based administration
Limit system, tenant, contact-center, and user administration according to assigned roles and permissions.
Data protection
Protect credentials and customer media using platform controls together with the security capabilities of the selected storage and infrastructure.
Protected credentials
Selected integration, storage, provider, and service credentials are encrypted before database storage and masked in forms.
Secure Password Mode
Prevent administrators from retrieving user passwords and use email-based reset and required-change workflows.
Configurable retention
Apply supported retention settings to voicemail, recordings, transcripts, and locally cached object-storage files.
External object storage
Store supported media in configured S3-compatible storage and apply encryption and access policies at that storage service.
Network & voice security
Configure protections for SIP and media traffic according to trunks, endpoints, certificates, and network design.
SIP edge controls
Use the integrated signaling layer for SIP normalization, topology handling, routing policy, and access controls.
STIR/SHAKEN
Configure caller-ID attestation for supported outbound calling arrangements.
Encrypted signaling and media
Configure TLS for SIP signaling and SRTP or DTLS-SRTP where the connected endpoints support it.
Tenant boundaries
Keep tenant configuration and delegated administrative access separated within the multi-tenant data model.
Operational controls
Activity history
Review recorded changes for supported configuration and CRM objects.
API authentication
Use revocable API keys, authorized account credentials, or authenticated browser sessions.
Recording policies
Choose which supported calls are recorded and apply tenant-specific retention settings.
Deployment models that match your security posture
The infrastructure boundary and operating responsibility are part of the security design:
- Provider-operated multi-tenant platform — the provider selects and operates the infrastructure.
- Thirdlane-operated multi-tenant platform — Thirdlane operates the underlying platform for the provider.
- Dedicated customer deployment — an MSP or integrator delivers a separate environment for one organization.
Review the security controls in context.
Discuss identity, network, storage, retention, administration, and deployment responsibilities with our team.