Legal
Security Policy
Last updated: January 2026
Network security
- Redundant, hardened POPs with private carrier interconnects.
- DDoS mitigation and rate-limiting at the edge.
- 24/7 NOC monitoring and anomaly detection.
Application security
- Least-privilege access controls and audited administrative actions.
- Signed software artifacts and change-managed deployments.
- Regular vulnerability scanning and third-party assessments.
Voice traffic security
- Optional TLS for SIP signaling and SRTP for media.
- IP ACLs, credential authentication and destination whitelists.
- Fraud detection with automated alerts and blocking.
Data security
- Encryption in transit for customer data.
- Role-based access with strong authentication for internal systems.
- Backups and tested recovery procedures.
Responsible disclosure
Report suspected vulnerabilities to Broadwayvoip.it25@gmail.com. We appreciate coordinated disclosure and will respond promptly.