Corinne by Reverie Corinne by Reverie

Security & compliance

Encrypted is the only setting

Reverie Tech’s day job is keeping other people’s systems from being broken into. It would be strange to then sell a phone system that sends conversations across a network in the clear, so Corinne does not have that mode.

TLS
Every signalling connection, including inside your office
SRTP
Every audio stream, in both directions
Per‑tenant
Recording and voicemail encrypted with your own keys
Every change
Audited with actor, before, after and source address

Encryption

Including on your own network

Many systems encrypt the leg between your office and the provider, then carry calls in the clear between the server and the handsets on your desks. The reasoning is that your LAN is trusted. It is not. Most incidents we are called to begin with something already inside the building: a compromised laptop, a device somebody plugged in, a guest network that was not as separate as everyone believed.

In Corinne, the handset on the desk speaks TLS to the platform and the audio is SRTP‑encrypted from the phone itself. There is no configuration in which a call on your network is readable by anything that can see the wire.

What this rules out. Unencrypted SIP is not a supported configuration. If you own handsets too old to do encrypted SIP, they cannot join, and we will tell you that during the inventory rather than after the invoice — send us your handset models and we will tell you which ones come with you.
A server rack with neatly bundled network cabling lit in blue, patch panels and switch port lights visible.
The platform runs on hardware Reverie Tech owns and operates.

What is encrypted, where

Desk phone → platformTLS + SRTP
Softphone → platformTLS + SRTP
Platform → carrierEncrypted
Voicemail at restEncrypted
Recordings at restEncrypted
Portal and admin consoleHTTPS only

Once a call leaves for the public phone network it travels on carrier infrastructure, which no provider controls. That is true of every phone system, ours included.

Keeping customers apart

Corinne runs many businesses on one platform. The interesting question is not whether we intend to keep them separate — everyone intends that, but what happens when a piece of software forgets to.

Separation in the database itself

Isolation is enforced by the database, underneath the application, so a query that forgets to filter by customer returns nothing rather than returning somebody else’s data. The application’s own checks are a second layer, not the only one.

Credentials bound to one company

A phone’s credential is cryptographically tied to the company it belongs to. We tested the obvious attack — using a valid account from one business to register as an extension at another, and it is refused.

No stored passwords to steal

We do not keep your handsets’ SIP passwords in a readable form, by design. It is also why a handset must be re‑provisioned rather than reconfigured if certain platform details change — a deliberate trade we made in favor of not holding the plaintext.

Toll fraud capped in advance

Every company has a ceiling on simultaneous calls and on how fast calls can be placed, and international dialing is off unless you ask. If a credential is ever stolen, the bill is bounded before anyone notices.

An audit trail that cannot be tidied

Every configuration change records who made it, which company it affected, what it was before, what it became, and the address it came from. The log is append‑only.

Your voice stays on our equipment

Voicemail transcription runs on hardware we own and operate, reachable only from inside the platform. Recordings of your customers are not uploaded to a third‑party service for processing. For a practice handling protected health information that removes a subprocessor entirely — see healthcare.

Operations

Watched from outside its own failure domain

A monitoring system that runs on the same box as the thing it monitors reports nothing at all when that box dies, which is precisely the moment you needed it. Corinne’s platform sends a regular heartbeat to a service that runs somewhere else entirely. If the heartbeat stops, that external service raises the alarm.

Alerts reach a person on two independent channels at once, and a critical alert repeats until somebody acknowledges it rather than scrolling past. Every alert is recorded before we try to deliver it, so a delivery failure leaves evidence instead of silence.

Why we are specific about this. We found this problem in our own platform by measuring it: a mail configuration had been silently refusing alert notifications, and nothing was watching the thing that counts refusals. The design above is what came out of fixing it.

Where it runs

Corinne runs on hardware Reverie Tech owns, in a datacenter certified to SOC 2 Type II and ISO 27001. That certification covers what a facility is responsible for: physical access control, power, cooling, environmental monitoring and the operational discipline around them.

What it does not cover. Those are the building’s certifications, not Corinne’s. The software itself has not been through a SOC 2 or ISO 27001 audit of its own. We say so plainly because a procurement review will establish it anyway, and because a vendor who blurs that line is telling you something about how they handle the rest.

Backups and recovery

  • Continuous backup of the platform database, with the transaction stream archived as it is written
  • Backups stored on separate storage from the live system, so a backup filling up cannot stop calls
  • Restores rehearsed, not assumed — a backup nobody has restored is a hypothesis
  • Recordings and voicemail on dedicated storage, with retention you set

Access to your data

  • Reverie staff access is separate from customer access and is logged
  • The customer portal has no privileged database access — it uses the same interface a third party would
  • Recording is off until someone with the authority turns it on, and turning it on is audited

Ask us the hard questions

We will answer specifically, and tell you where the limits are. If you have a security team, put us in front of them.