Security of Voice-to-SaaS: PIN, 2FA, and Capability Gateway
Enterprise-grade security for voice-enabled business tools
How CallMerlin secures voice access to your business tools: PIN verification, 2FA (authenticator app or SMS), capability-level permissions, and EU-hosted encryption.
Key takeaways
- PIN + 2FA (authenticator app or SMS), same security level as online banking
- Capability Gateway enforces permissions in code, not by AI instructions
- AES-256-GCM encryption for all stored credentials
- All data hosted in the EU, GDPR compliant
- 90-day conversation log retention, exportable and anonymizable
- Domain whitelist prevents unauthorized widget embedding
Chapters
The Security Challenge of Voice Interfaces
Voice access to business data requires stronger security than traditional dashboards.
Multi-Layer Authentication
6-digit PIN verification, optional 2FA via authenticator app (recommended) or SMS, hands-free verification for trusted numbers.
Capability Gateway: Server-Side Permission Enforcement
Permissions enforced in code, not by AI. Each tool action requires an explicit capability grant.
Data Encryption and Storage
AES-256-GCM encryption for all credentials. EU-hosted infrastructure. Data never leaves the EU.
GDPR Compliance
Per-language consent prompts, anonymous conversation logs, configurable data retention, data minimization.
Widget Security
Domain whitelist, CSP-friendly embedding, Shadow DOM isolation, no business data in the widget itself.
Compliance Checklist
Point-by-point checklist for CISO approval: encryption, authentication, data residency, audit logging.