Skip to content

Security and trust: your communications, protected by design.

Overview

Security is not a separate module: it is built into how every device connects, how every user signs in and how every system integrates. This is what TelHarbor does, with no fine print.

Connection

No active VPN, no service.

Your company communications are not exposed on the internet: they travel through an encrypted tunnel for each device.

Mandatory VPN

The softphone, chat, remote support and file transfer only start with the VPN tunnel active and validated. If the tunnel drops, they stop; when it returns, they reconnect on their own.

One tunnel per device

Each device has its own tunnel, address and keys. Keys are never shared between devices, and removing one does not affect the rest.

Encrypted calls

The app voice and signaling travel inside the encrypted tunnel to the phone system, not over the open internet.

Access

Everyone signs in with their own account, and it is logged.

Two-step verification

Besides the password, a code by email or WhatsApp. Trusted devices are remembered for a few days and can be revoked.

Protected passwords

Stored with irreversible hashing: nobody at TelHarbor can read them.

Session limit

Each user has a maximum number of open sessions, and the administrator can close a session remotely.

Security alerts

Users are notified when their password, email or phone changes, and when someone signs in from a new device.

Bot protection

Sign-in and forms filter automated attempts.

Role permissions

Administrator, supervisor or agent, with access by module, queue or extension. Everyone sees only what they should.

Access and activity log

Successful, failed and blocked sign-ins with date, IP and device, plus the key actions of every user.

Supervision with permission

Only authorized roles can listen to or barge into a call, and a private extension cannot be monitored.

Integrations

Your systems connect to TelHarbor without opening doors.

API keys

Each key is shown only once and stored hashed. Revoke or regenerate it at any time.

Scopes and limits

Each key gets only the scopes it needs, an IP allowlist (IPv4 and IPv6), a per-minute limit and a daily quota. All usage is logged.

Signed webhooks

Events sent to your system carry a timestamped HMAC signature and are only delivered to public HTTPS addresses.

Verification codes

One-time codes are stored hashed, expire after 10 minutes and allow at most 5 attempts.

Operations and compliance

Our own infrastructure and clear rules.

Datacenter in Costa Rica

The platform and its data are hosted in the TelHarbor datacenter in Costa Rica.

Encrypted connections

The website and portals run over HTTPS only, with HSTS and security headers on every response.

Licensed provider

Servicios Technologicos Antares de Costa Rica S.A. is a telecommunications provider authorized by SUTEL, the Costa Rica regulator.

Messaging consent

SMS opt-in consent is recorded with date, IP and the exact text accepted, and it is never sold or shared.

Service status

The footer of every page shows the current status of the platform.

FAQ

Security FAQ

Where is my data stored?

In the TelHarbor datacenter in Costa Rica. Calls and messages to the public network go through the carriers needed to deliver them.

What if an employee loses their laptop?

The administrator closes their open sessions, revokes the trusted device and disables their access. Without its VPN tunnel, the app on that device cannot connect.

Who can listen to my calls?

Only the roles your administrator authorizes, and never an extension marked as private.

Are you ISO 27001 certified?

Our security policy is based on ISO 27001:2022. If your company assesses vendors with a security questionnaire, we will complete it.

Can I restrict where the API is used from?

Yes. Each key only accepts the IP addresses you specify, IPv4 or IPv6, and only the scopes assigned to it.

Does your company assess vendor security?

We complete your questionnaire and show you every measure on the platform.

Talk to an advisor