API keys
Hashed at rest, displayed once, and instantly revocable.
Webhooks
Signed with HMAC-SHA256. Verify every delivery before trusting it.
Hosted Sessions
LiveKit tokens are short-lived and room-scoped. API keys never reach clients.
Bring Your Own Room
No standing credential exchange. You mint one per-call token; Chert never sees your LiveKit keys.
Caller identity
Caller handles are hashed in webhook payloads.
Transcripts
Consent-gated, encrypted at rest, authenticated, and deletable on request.