3CX security statement

Status
Not open for further replies.

JonGair

Free User
Joined
Jul 11, 2019
Messages
4
Reaction score
1
Is there any security statement or documentation which provides assurances around how the 3CX WebMeeting system operates ? Most of the 3CX security is clearly defined and sits within the control of the end user since it is managed within your VM or appliance. However, the webmeeting process uses 3CX hosted components acting as an MCU/SFU so I am assuming this will not be encrypted video/audio end to end, with the hosting service managing the conversations between all parties.

Just wondering how the service is protected and what 3CX are committed to to ensure our audio/video traffic is not intercepted. Cannot really see anything on the privacy policy since it tends to deal more with the website interaction and any data held by 3CX in the process.

I will have to carry out a data privacy impact assessment as part of the GDPR process if my company is going to start using this solution so need a bit more detail to carry this out.

Thanks

Jon
 
  • Like
Reactions: cobaltit
Have you used Webmeeting at all? Last time I checked everything was over HTTPS. Which means simply means it's encrypted, not that it can't be intercepted.

And I almost spit out my drink at the committed line. Every company is equally 'committed' to security on paper so feel free to take anyone's blurb for that.

Also, I don't believe 3CX actually sees that much outside of the recordings if enabled. WebRTC is encrypted by default (no option otherwise) and I believe the now AWS hosted mediation servers are just that. But yes an updated statement or document from 3CX would make folks jobs easier since things like GDPR are an unfortunate necessity in today's world.
 
Last edited:
  • Like
Reactions: Evolute IT
An updated privacy policy for WebMeeting is something we're preparing right now to address questions like these. It will be available soon.
 
Last edited:
That sounds great, thanks. Can we try and cover off the following when pulling together the privacy statement for webmeeting.
  • flow of audio/video data when in flight over the network.
  • any data stored at rest and how it is protected, including retention period and how it is secured/deleted
  • ways of minimising the data flows to stay within your own particular region. I can see that the MCU can be automatic or specific go one server. It would be great if this could have a feature to limit by region (say UK or EU servers to still provide some form of resilience rather than relying on one server always being up)
Thanks

Jon
 
  • ways of minimising the data flows to stay within your own particular region. I can see that the MCU can be automatic or specific go one server. It would be great if this could have a feature to limit by region (say UK or EU servers to still provide some form of resilience rather than relying on one server always being up)
This will be included in the privacy policy in more detail. Also what you've mentioned is exactly how WebMeeting's geolocation works.
 
Any timescales in relation to when this revised webmeeting privacy policy will be released ?

Thanks

Jon
 
Not yet, we're still working on it. It's not a quick and easy thing to do and will need time to be reviewed and published.
 
Status
Not open for further replies.

Forum statistics

Threads
111,933
Messages
589,809
Members
164,807
Latest member
Smax