This page describes how Gravix Cloud protects calls, streams and accounts, what you need to do on your side, and how to report a security problem.
Need more detail than this page gives, or a signed agreement for your company? Email sales@gravixcloud.com or call +880 1703-449000.
Encryption in transit
Audio and video between your users and our service are encrypted in transit with DTLS-SRTP, the standard used for real-time media on the web and on mobile. The connections your app uses to join rooms and exchange control messages are encrypted with TLS.
This is encryption in transit, not end-to-end encryption: media is decrypted inside our service so it can be routed to the other participants.
Short-lived access tokens
Apps do not need your secret key. Your server uses the secret key to issue a short-lived access token for each user, and the app joins a room with that token. A token only works for a limited time, so a leaked token is far less useful than a leaked key.
What you should do
Security is shared between us and you. On your side:
- keep secret keys on your server only, out of app code and out of public code repositories;
- issue tokens only to users your app has signed in, with the shortest lifetime that works for you;
- tell us straight away if you think a secret key has been exposed;
- tell your users how their camera, microphone and media are used, in your own privacy policy.
Report a vulnerability
If you find a security problem in Gravix Cloud, email sales@gravixcloud.com with "Security report" in the subject. Include what you found, the steps to reproduce it and how to reach you. Please give us a reasonable chance to fix the problem before you share it publicly, and do not access other people's data or disrupt the service while testing.
Security reviews and questionnaires
If your company needs a security questionnaire or more detail before you choose Gravix Cloud, contact sales@gravixcloud.com and tell us what your review requires.
