Cloud telephony that keeps records and protects access
Security is more than call encryption. MaxiPBX logs sensitive actions, encrypts secrets, separates tenants, restricts rights and lets you strengthen administrator accounts with two-factor authentication.
Two-factor authentication and sensitive accounts
Administrative accounts can be protected by two-factor TOTP authentication and single-use recovery codes.
- 2FA TOTP compatible with Google Authenticator, Aegis, FreeOTP and standard applications
- Recovery codes hashed and single-use
- Password reset governed by system administrator
- Ability to enforce 2FA by role in sensitive environments
Complete action logging
Every significant operation must leave an auditable trail: who, when, from which IP address, on which target and with what result.
- Creation, modification, deletion, login and system actions logged
- Author, tenant, IP address, action, target, result and summary retained
- Automatic masking of passwords, secrets, tokens and sensitive data
- Filters by author, tenant, action type and system actions
Encryption and web hardening
Interfaces, APIs and telephony flows use modern protocols, with separation between phone compatibility and web security.
- SIP signaling in TLS and audio in SRTP
- Web interface and API limited to TLS 1.2 / 1.3 with modern cipher suites
- Legacy protocols and weak algorithms removed on the browser side
- HTTP security headers and HTML sanitization on the server side
Protected technical secrets
API keys, trunk passwords, CRM tokens and TTS identifiers are not ordinary text fields.
- Secrets encrypted at rest and never redisplayed after save
- Test trunk passwords protected in the certification program
- CRM tokens and vendor keys isolated by tenant
- Attachments and support content controlled and served by authenticated access
Tenant isolation and permissions
The platform is designed for wholesalers, resellers, tenants and master administrators without scope leakage.
- Instances and data separated by customer
- Delegated administration by wholesaler, sub-wholesaler, reseller or tenant
- One-click access to PBX logged and server-side
- Remote actions executed without opening inbound SSH when remote management is used
Frequently asked questions
Are all actions really logged?
The objective is that every creation, modification, deletion, login or system action leaves an audit entry. Audit is designed in best-effort mode: it must not break the business action, but it preserves useful metadata.
Do passwords and secrets appear in the logs?
No. Sensitive fields are automatically masked. Secrets are encrypted at rest and are not redisplayed after recording.
Is 2FA mandatory?
It can be enabled per administrator account and enforced by role according to the chosen policy. Regular telephony users are not affected by default.
Need to validate MaxiPBX with your IT director?
We can detail the architecture, logs, access, encryption and permissions model in a technical discussion.