Security

Last updated: August 6, 2026

What Callbax stores

The minimum needed to contact your customer about their appointment: their phone number, the appointment time, and their name where your calendar or upload supplies one.

Callbax does not store appointment descriptions, notes, locations, attachments, or the reason for the visit. Raw calendar event data is processed in memory and discarded once the appointment time and phone number have been extracted.

How it is protected

  • Customer phone numbers and names are encrypted at rest with AES-256-GCM.
  • Phone numbers are additionally hashed with HMAC-SHA256 for deduplication and opt-out matching. The hash is not reversible.
  • All data is stored in the European Union (Frankfurt, Germany), encrypted at rest and in transit.
  • Logs redact phone numbers to the last four digits.

Calendar access

Calendar connections are read-only, enforced by the permission Callbax requests rather than by policy: calendar.readonly for Google and Calendars.Read for Microsoft. Callbax cannot create, move, edit or delete an event even if it tried. You can revoke access at any time from your Google or Microsoft account, or by disconnecting the source in Callbax.

Contacting your customers

Nothing is sent until you switch it on. Every planned message and call is visible before it goes out and can be stopped individually. A customer who replies STOP is recorded permanently and cannot be re-contacted by that business — including by a later import — and that suppression cannot be undone by the business.

Healthcare and protected health information

Callbax does not offer a Business Associate Agreement, and must not be used to process protected health information. It is not offered for use by, or on behalf of, HIPAA covered entities or their business associates. If you are subject to HIPAA, do not connect a calendar or upload a file whose contents would constitute protected health information.

This is a deliberate limit on who Callbax is for today, not a statement about the strength of the controls above.

What Callbax does not claim

Callbax holds no SOC 2 report, no ISO 27001 certificate, and no independent security audit. It has not been penetration tested by a third party. We would rather say so than imply a programme that does not exist.

Reporting a problem

If you believe you have found a security issue, email hello@callbax.ai. Please include enough detail to reproduce it. We will acknowledge your report and will not pursue action against good-faith research.