Skip to main content
Security is shared. Klariqo protects the compliance record system and the evidence chain. You control the dialer environment, call scripts, access decisions, consent practices, and retention policy around your own operations. This page explains that split.

What Klariqo does

1

Signs compliance records

Klariqo signs records for calls covered by an active scorecard. The record is signed with a JWS signature using RS256, and the signature carries Klariqo’s signing certificate.
2

Makes changes detectable

A signed record is tamper-evident. If the signed vCon is changed after signing, verification fails.
3

Fingerprints the recording

A SHA-512 content hash fingerprints the recording inside the record. This helps tie the record to the recording content.
4

Secures dialer connections

Klariqo uses SIP digest authentication for dialer connections. Audio travels over an encrypted WebSocket.
5

Stores recordings encrypted

Recordings are kept in encrypted storage.
6

Applies a trusted timestamp

Klariqo obtains an RFC 3161 trusted timestamp from DigiCert over the record’s fingerprint, proving the record existed at a point in time. DigiCert does not receive the transcript, audio, phone numbers, or QA content.

What you own

You are responsible for the systems and decisions you control.

Shared responsibility in practice

Klariqo evidence layer

Signed records, content hashes, QA results, trusted timestamps, and verification.

Your operating layer

Scripts, consent, dialer administration, access control, retention, and legal review.

What security does not mean

Security controls help protect the record and its provenance. They do not decide whether a call was legally placed, whether a script is approved, or whether your retention policy is correct.
Klariqo provides evidence, provenance, and audit-readiness. Klariqo does not make you compliant, prove consent by itself, win a lawsuit, or replace your scripts, retention policy, access decisions, dialer security, or counsel review.