Legal

Security

An overview of how TechExtension approaches security for the AsterCTI website, Customer Portal and the support of your deployment.

Security is part of how TechExtension builds and operates AsterCTI, from the public website through to the Customer Portal and the systems our support team uses. This page describes the practices we actually follow. We don't claim formal certifications (such as SOC 2, ISO 27001 or PCI-DSS) or a formal third-party penetration-testing program here, because we want this page to reflect what is genuinely in place rather than aspirational claims. If a customer or prospect requires a formal security review as part of a purchase, contact us and we're happy to discuss it directly.

1. Application Access Control

AsterCTI's web areas are separated by role: the public marketing site, the Customer Portal (customer accounts, orders, subscriptions and the Helpdesk), and internal administration tools are kept as distinct, access-controlled areas rather than a single shared surface. Customer Portal accounts require sign-in, and account passwords are stored using one-way password hashing — never in plain text — with reset flows available if you forget your password.

2. Data Handling Practices

Database queries used across the site are built with parameterized/prepared statements rather than inserting raw input directly into SQL, which is a standard defense against SQL-injection attacks. Administrator-entered content that is rendered back to visitors (for example, SEO fields and documentation content) is sanitized and safety-encoded before it is stored or displayed, to reduce the risk of stored cross-site scripting.

3. Payments

Installation and renewal payments can be made through PayPal, Wise, or direct bank transfer. For PayPal payments, we do not collect or store full payment card numbers on our own servers — that information is handled directly by PayPal under its own security and compliance program. Wise and bank transfer payments are arranged by invoice and settled directly between you and your bank or Wise, without your account credentials passing through our servers.

4. Form and Account Abuse Protection

The Contact form and Customer Portal signup page use Google reCAPTCHA v3 to help filter automated and abusive submissions before they reach our team or create an account.

5. Transport and Hosting

The AsterCTI website and Customer Portal are served over HTTPS at astercti.techextension.com. Administrative areas (teadmin), the customer portal, license portal, and other internal or backend paths are excluded from search engine indexing via robots.txt and are not part of the publicly linked site.

6. Support and Access Requests

When our team needs access to a customer's PBX or CRM environment to install or troubleshoot AsterCTI, we ask only for the access required to perform that specific work, and we expect customers to manage and, where appropriate, revoke that access once it is no longer needed. If you believe your Customer Portal account or an integration credential has been compromised, contact us immediately at support@techextension.com so we can help you secure it.

7. Third-Party Dependencies

AsterCTI integrates with third-party Asterisk-based PBX distributions and CRM platforms that TechExtension does not control. The overall security of a deployment also depends on how those third-party systems, and the customer's own network and hosting environment, are configured and maintained. We recommend customers keep their PBX, CRM and server software patched and follow their own vendors' security guidance alongside using AsterCTI.

8. Vulnerability Reports

If you believe you've found a security issue affecting the AsterCTI website, Customer Portal, or software, please report it to support@techextension.com with enough detail for us to reproduce and investigate it. We ask that you avoid accessing, modifying or exfiltrating other customers' data while investigating, and we will acknowledge and follow up on reports we receive in good faith.

9. Changes to This Page

We may update this page as our practices evolve. When we do, we will revise the effective date above. This page describes general practices and does not constitute a guarantee or contractual commitment; specific security commitments, where applicable, are addressed in an order confirmation or written agreement.

10. Contact Us

For security questions, contact support@techextension.com, or reach our sales team at sales@techextension.com for pre-purchase questions.

Have a security question before you buy?

Our team is happy to walk through how AsterCTI fits your requirements.

Contact Us