Security and trust

The keys to your Twilio account stay with you

Bring your own Twilio is a security posture as much as a billing model. Here is exactly how Syncodial connects to your account and protects your data.

The essentials

We never hold your Auth Token

You create a scoped Standard API key in the Twilio console and give that to Syncodial. Your Auth Token, the master key to your account, never leaves Twilio. That means the worst case is bounded: a scoped key can be rotated without touching your account.

Least privilege by design

Inbound webhooks are authenticated with a secret URL token and an HMAC signature, so only genuine Twilio traffic is accepted. Stored credentials are encrypted at rest. Access inside a workspace follows a default-deny permission model.

Your data stays portable

You can export your entire workspace as a single JSON file at any time, and you can request workspace deletion with a grace window before a full purge. Your Twilio account, numbers, and usage are always yours.

Security and ownership

The keys to your Twilio account stay with you

The most important control comes first: we never hold the keys to your account. Everything below is shipped in the product today.

Auth Token never stored

You create a scoped Standard API key. We never store your Twilio Auth Token.

Encrypted credentials

Stored Twilio credentials are encrypted at rest.

Signed webhooks

Inbound webhooks use a secret URL token and an HMAC signature.

Two-factor authentication

TOTP two-factor with an authenticator app, built in.

Recovery codes

Single-use recovery codes for when you lose your device.

Session management

See active sessions and sign out other devices.

Role based permissions

Six roles and a granular permission matrix, default deny.

Audit logs

High value actions are recorded for review.

Data export

Export your workspace data as a single JSON file.

Workspace deletion

Request deletion with a grace window, then a full purge.

We describe only what is shipped. We do not claim security certifications we do not hold.

FAQ

Questions, answered plainly

Where an answer depends on Twilio or Meta availability, we say so.

Does Syncodial store my Auth Token?
No. We never store your Twilio Auth Token. You create a scoped Standard API key in the Twilio console, and Syncodial uses that. Inbound webhooks are authenticated with a secret URL token and an HMAC signature.
Can I cancel?
Yes. You can cancel your software subscription at any time from the billing page. You can also export your workspace data and request workspace deletion.
Is Twilio Connect supported?
Not at launch. We use a customer owned scoped API key because it supports the full feature set, including the browser softphone. We researched Twilio Connect and will revisit it only if it clears those capabilities.

Connect Twilio with confidence

A guided wizard walks you through the scoped API key. You keep the account, and we keep the keys off our servers.

14-day Pro trial. No card required.