Security at ZuteSIP: account protection, payments and data handling
Short answer: ZuteSIP protects accounts with optional two-factor authentication and an audit log of every sign-in, and asks only for an email address at sign-up. Payments are made in USDT or USDC on public blockchains, so no card or bank details are ever collected. Security issues can be reported to support@zutesipdialer.com.
Your ZuteSIP account controls real phone numbers, and those numbers often receive verification codes for other services. That makes account security more than a formality, so this page explains what protects your account, what data we hold, and how to report a problem.
Account security: 2FA and a sign-in audit log
Every ZuteSIP account can turn on two-factor authentication (2FA). With 2FA enabled, signing in needs a second factor in addition to your password, so a leaked or guessed password alone is not enough to open your dashboard. We recommend enabling it as soon as you buy your first number.
The dashboard also keeps an audit log of sign-ins. Checking it from time to time lets you spot a sign-in you don't recognise. If you see one, change your password, make sure 2FA is on, and open a support ticket so we can look at it with you.
- Turn on 2FA in your account settings.
- Use a unique password for ZuteSIP that you don't use on any other site.
- Review the sign-in audit log after travelling or signing in from a new device.
- Keep the email address on your account secure, because it is how you sign up and how we contact you.
Email-only sign-up: less data to protect
Creating an account needs only an email address. We don't ask for your name, home address, date of birth or ID documents to open an account, which means there is simply less personal data stored about you in the first place.
Collecting less is one of the most effective security measures there is: data that was never collected cannot be exposed. Details about what we do keep, and why, are in our privacy policy.
SIP credentials and calling security
Each number has its own SIP username and password, shown on that number's page in the dashboard. They are separate from your account password, so a SIP app or PBX never needs your dashboard login. Treat them like a password: enter them only in software you trust, and don't paste them into shared documents or support chats.
Our SIP server accepts digest authentication and supports signalling over TLS on port 5061 in addition to UDP/TCP on port 5060. Media encryption (SRTP) is not part of the service. If you prefer not to configure a SIP app at all, the browser web dialer lets you call from your numbers after signing in to the dashboard.
Payments on public blockchains: no card data stored
ZuteSIP accepts only USDT and USDC, on Tron, BNB Smart Chain, Polygon, Base or Solana, either through a prepaid wallet or directly at checkout. We don't accept card, PayPal or bank payments, so we never collect or store card numbers, bank account details or billing addresses.
A crypto payment is recorded on a public blockchain as a transaction between wallet addresses. That record is public by design and is not something we control. What we keep in your account is the order and the transaction details needed to credit your payment and answer billing questions.
How we handle your data
We process the data needed to run the service: your email address, account and security settings, sign-in records, your numbers, and the SMS and call logs shown in your dashboard. We use it to deliver the service, keep accounts secure, handle support and billing, and meet legal obligations.
The full picture, including cookies and analytics, the legal bases we rely on, your rights and how to exercise them, is set out in the privacy policy.
Abuse handling
Real numbers on national networks only stay useful if they aren't used for spam, fraud or harassment. Our acceptable use policy lists what is and isn't allowed, and accounts that break it can be warned, suspended or closed.
If a ZuteSIP number is being used to contact you in a way that breaks the policy, email support@zutesipdialer.com with the number, the date and time, and what happened. We review every report.
Responsible disclosure: reporting a security issue
If you believe you have found a security vulnerability in zutesipdialer.com, the dashboard or our SIP service, please report it to support@zutesipdialer.com. Our security contact details are also published in machine-readable form at /.well-known/security.txt.
Please give us a reasonable chance to investigate and fix the issue before sharing it publicly, and don't access, change or delete data that isn't yours while testing.
- A clear description of the issue and where it occurs (URL, endpoint or SIP component).
- Steps to reproduce it, and what an attacker could achieve.
- Any proof-of-concept, screenshots or request logs, with other people's data removed.
- How we can reach you for follow-up questions.
What this page does not claim
This page describes the protections that exist in ZuteSIP today. We don't claim third-party security certifications or audits here. If something you need for a security review isn't covered, ask us at support@zutesipdialer.com and we'll tell you what we can.
Frequently asked questions
Does ZuteSIP support two-factor authentication?
Yes. Every account can enable 2FA, so signing in needs a second factor as well as your password. We recommend turning it on right after sign-up.
Can I check recent sign-ins to my account?
Yes. The dashboard keeps an audit log of sign-ins, which you can check for any sign-in you don't recognise.
Does ZuteSIP store my card details?
No. Payments are made only in USDT or USDC on public blockchains, so we never collect card or bank details.
What personal information do I need to sign up?
Only an email address. We don't ask for ID documents, a home address or a phone number to open an account.
Are calls encrypted?
SIP signalling can run over TLS on port 5061. Media encryption (SRTP) is not part of the service.
How do I report a security vulnerability?
Email support@zutesipdialer.com with a description and steps to reproduce. Our security contact is also listed at /.well-known/security.txt.