Every credential we hold is now encrypted with ChaCha20-Poly1305

Two changes to how SIMCOAI stores its own credentials and the secrets it holds on your behalf — a webhook signing secret, a connected AI provider key. Both are now encrypted at rest with ChaCha20-Poly1305, a published, independently reviewed authenticated encryption standard (RFC 8439) also used by Google, Apple and Cloudflare in their own production systems, using full 256-bit keys throughout. Every stored secret carries an authentication tag: if it is altered by even one bit, decryption is refused outright rather than returning a tampered value, and a secret held on your behalf is individually bound to your account, so a copy of one record cannot be read against another.

SIMCOAI's own operational credentials — the keys we use to reach our payment, calling, messaging and AI providers — moved out of a plain configuration file and into a dedicated, self-hosted secrets manager running on our own infrastructure, decrypted only in memory at boot and never written to disk as plain text. Nothing about how you use SIMCOAI changes. How we protect your data

All updatesOlder update →
Try SIMCOAI

See it working on your own phone line.

Start a 7-day trial and configure your AI front desk in the dashboard.