Security

Apply communications controls within your security architecture.

Thirdlane provides identity, administrative, credential, signaling, media, retention, and activity-history controls. Their effectiveness depends on deployment design, endpoint support, identity-provider policy, storage configuration, and day-to-day operation.

Identity & access

SSO and directory sync against the identity systems you already operate.

OIDC single sign-on

Configure supported named providers or another OpenID Connect provider for administrator and Connect sign-in.

Identity-provider MFA

Apply multi-factor authentication through the configured identity provider and its access policies.

Directory synchronization

Synchronize users from Microsoft, Okta, or LDAP with configurable mapping and connection testing.

Role-based administration

Limit system, tenant, contact-center, and user administration according to assigned roles and permissions.

Data protection

Protect credentials and customer media using platform controls together with the security capabilities of the selected storage and infrastructure.

Protected credentials

Selected integration, storage, provider, and service credentials are encrypted before database storage and masked in forms.

Secure Password Mode

Prevent administrators from retrieving user passwords and use email-based reset and required-change workflows.

Configurable retention

Apply supported retention settings to voicemail, recordings, transcripts, and locally cached object-storage files.

External object storage

Store supported media in configured S3-compatible storage and apply encryption and access policies at that storage service.

Network & voice security

Configure protections for SIP and media traffic according to trunks, endpoints, certificates, and network design.

SIP edge controls

Use the integrated signaling layer for SIP normalization, topology handling, routing policy, and access controls.

STIR/SHAKEN

Configure caller-ID attestation for supported outbound calling arrangements.

Encrypted signaling and media

Configure TLS for SIP signaling and SRTP or DTLS-SRTP where the connected endpoints support it.

Tenant boundaries

Keep tenant configuration and delegated administrative access separated within the multi-tenant data model.

Operational controls

Activity history

Review recorded changes for supported configuration and CRM objects.

API authentication

Use revocable API keys, authorized account credentials, or authenticated browser sessions.

Recording policies

Choose which supported calls are recorded and apply tenant-specific retention settings.

Deployment models that match your security posture

The infrastructure boundary and operating responsibility are part of the security design:

Review the security controls in context.

Discuss identity, network, storage, retention, administration, and deployment responsibilities with our team.