Security at Telegent
How we protect a carrier-grade AI mobile network, the practices behind the platform, and how to responsibly report a vulnerability.
Last updated: July 1, 2026
Our security program is maturing alongside the platform, and the policies below are being finalized. This page describes our approach and commitments and will be reviewed by qualified counsel and security leadership before launch.
Our Security Approach
Telegent operates a carrier-grade platform that carries real voice, messaging, and cellular traffic on the largest U.S. mobile carrier. Because that traffic is sensitive, security is a foundational part of how we design, build, and run the Services, not an afterthought. We take a defense-in-depth approach across our infrastructure, applications, and operations.
Encryption
We encrypt data in transit using industry-standard protocols (TLS) and encrypt data at rest in our systems. Secrets and keys are managed through dedicated key management, with access restricted to the systems and personnel that require it.
Least-privilege access
Access to production systems and customer data follows the principle of least privilege. We use role-based access controls, require strong authentication for internal systems, and review access periodically. Administrative actions are logged.
Network segmentation
Production networks are segmented from corporate and development environments, and sensitive services are isolated. Network controls limit lateral movement and restrict traffic to what each component needs to function.
Logging and monitoring
We collect logs and telemetry across the platform to detect anomalies, investigate issues, and support incident response. Monitoring and alerting help us identify suspicious activity and respond quickly.
Secure software development
Security is built into our software development lifecycle (SDLC). We use code review, dependency and vulnerability scanning, and testing as part of our release process, and we work to remediate identified issues on a risk-prioritized basis.
Vendor and subprocessor review
We evaluate the security practices of the vendors and subprocessors that support the Services and bind them by contract to appropriate safeguards. We periodically review these relationships as our platform evolves.
Incident response
We maintain an incident response process for identifying, containing, and remediating security events, and for notifying affected parties where required by law or contract.
Compliance roadmap
Telegent is working toward SOC 2 Type II. We do not currently claim to hold that or any other certification; instead, we are building the controls, evidence, and processes needed to support a formal audit. We will update this page as we reach milestones. If you have specific compliance requirements, contact us at security@telegent.com and we will share our current status.
Coordinated Vulnerability Disclosure
We value the work of security researchers and the broader community in helping keep the platform safe. If you believe you have found a security vulnerability in a Telegent system, we want to hear from you and will work with you to understand and resolve the issue quickly.
Scope
This program covers Telegent-owned production systems and services, including our websites, consoles, and public APIs. Systems operated by third parties, underlying carriers, or our customers are out of scope. If you are unsure whether something is in scope, ask us before testing.
How to report
Send your report to security@telegent.com. Please include enough detail to reproduce the issue: affected systems or URLs, a description of the vulnerability, step-by-step reproduction, and any proof-of-concept material. Where possible, encrypt sensitive details or ask us for a secure channel. Please do not disclose the issue publicly until we have had a reasonable opportunity to remediate it.
Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your activities authorized, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you related to your research. If legal action is initiated by a third party against you for activity that complied with this policy, we will make this authorization known. This safe harbor does not apply to activity that violates the law or the boundaries below.
What not to do
- Do not access, modify, or exfiltrate data that does not belong to you.
- Do not perform denial-of-service (DoS/DDoS) testing or actions that degrade or disrupt the Services.
- Do not use social engineering, phishing, or physical attacks against Telegent personnel, customers, or facilities.
- Do not run automated scanning at volumes that could harm systems, and stop testing if you encounter user data.
- Do not violate any applicable law or the privacy of others.
Our commitment and response timeline
When you report an issue in good faith, we aim to:
- Acknowledge your report within 3 business days.
- Provide an initial assessment or triage within 10 business days.
- Keep you informed of progress toward remediation.
- Credit you for your contribution, with your permission, once the issue is resolved.
Timelines are targets and may vary with the complexity and severity of an issue. We appreciate your patience and your help in keeping Telegent secure. Reach us any time at security@telegent.com.
Building on infrastructure you can trust.
Talk to our team about security requirements, our compliance roadmap, or how Telegent protects communications across a carrier-grade network.