Product security

Security built around your existing phone system.

Tabd connects employees to assigned SIP extensions in Chrome. These are the security controls implemented in the product today, plus the deployment responsibilities that remain with each PBX environment.

Encrypted SIP credentials

SIP passwords are encrypted with AES-256-GCM before storage. The application decrypts them only when an authorized calling flow needs the assigned extension configuration.

Workspace-scoped access

Product data is associated with a workspace and membership. Owner, admin, and member roles separate workspace management capabilities from a member's personal account and calling views.

Authenticated dashboard routes

Dashboard and management pages require an authenticated product session. Public search crawlers are also instructed not to index protected application routes.

Secure deployment configuration

Production browser calling should use HTTPS and secure WebSocket endpoints, with correctly configured SIP, Janus, STUN, TURN, firewall, and certificate settings. Compatibility and media paths should be validated before rollout.

Questions or a security report?

Contact the Tabd team with deployment questions or enough detail to reproduce a potential security issue.

Contact Tabd