Back to whitepapers
Security

Security of Voice-to-SaaS: PIN, 2FA, and Capability Gateway

Enterprise-grade security for voice-enabled business tools

11 min read13 pagesCISOs, compliance officers, IT security teams

How CallMerlin secures voice access to your business tools: PIN verification, 2FA (authenticator app or SMS), capability-level permissions, and EU-hosted encryption.

Key takeaways

  • PIN + 2FA (authenticator app or SMS), same security level as online banking
  • Capability Gateway enforces permissions in code, not by AI instructions
  • AES-256-GCM encryption for all stored credentials
  • All data hosted in the EU, GDPR compliant
  • 90-day conversation log retention, exportable and anonymizable
  • Domain whitelist prevents unauthorized widget embedding

Chapters

1

The Security Challenge of Voice Interfaces

Voice access to business data requires stronger security than traditional dashboards.

2

Multi-Layer Authentication

6-digit PIN verification, optional 2FA via authenticator app (recommended) or SMS, hands-free verification for trusted numbers.

3

Capability Gateway: Server-Side Permission Enforcement

Permissions enforced in code, not by AI. Each tool action requires an explicit capability grant.

4

Data Encryption and Storage

AES-256-GCM encryption for all credentials. EU-hosted infrastructure. Data never leaves the EU.

5

GDPR Compliance

Per-language consent prompts, anonymous conversation logs, configurable data retention, data minimization.

6

Widget Security

Domain whitelist, CSP-friendly embedding, Shadow DOM isolation, no business data in the widget itself.

7

Compliance Checklist

Point-by-point checklist for CISO approval: encryption, authentication, data residency, audit logging.