Security

Security Practices

RingDesk uses session-based authentication, scoped tenant authorization, signed webhooks where providers support them, rate limits on auth and inbound lead paths, and Stripe-hosted payment collection.

Provider credentials and webhook secrets are kept in environment-managed secrets. Billing card data is handled by Stripe, not stored by RingDesk.

We do not claim SOC 2, HIPAA, or formal data residency guarantees on this page. Those require a signed agreement and supporting controls.

Report security concerns to hello@getringdesk.com.