Security
Built for regulated phone support
Invite-only access
No public sign-up. Every account is invited by a tenant owner or admin.
Short-lived tokens
Access tokens expire in 15 minutes and are held only in memory, never in local storage.
Rotating refresh sessions
Refresh tokens live in an HttpOnly, Secure cookie and rotate on every use, with per-session revocation.
Optional MFA
Tenants can require TOTP-based multi-factor authentication for every member.
Full audit trail
Every membership, key, and configuration change is logged with actor, IP, and timestamp.
Conversational agents your supervisors build and run.
© 2026 callmesh
Made in India