Redact Your Data
When you use Vonage communication APIs, server logs and transactional records of the activity are created. Transactional records of the activity are called communication detail records or call detail records (CDRs).
Server logs are retained between 15 and 30 days while the CDRs are stored for 13 months. Both server logs and CDRs can be viewed by our support staff for various purposes, including testing and debugging, diagnosing user issues, and reconciling CDRs against customers' transaction records.
The Auto-redact service and Redact API can be used to remove personal data from your CDRs and server logs (Advanced Auto-redact only). Details on how to enable the Redact API or Auto-redact service for your account are found below. Personal data generally includes the receiver phone number for outbound messages or calls and sender phone number for inbound messages or calls. For messages, personal data also includes the message content and for outbound SMS the IP address. Server logs store the same personal data as CDRs.
Upon redaction, the real personal data content in the redacted fields is overwritten with the string [REDACTED]. Personal data that is redacted is permanently deleted.
Customers can view the redacted CDRs using either the Vonage Reports API Reference, or the Customer Dashboard by navigating to Logs
The Auto-redact service provides a simple, blanket solution, automatically redacting all scopes across all services when enabled. For more fine-grained control, allowing you to choose which product, you can utilize the free Redact API.
Redact API
The Redact API provides Vonage customers with an endpoint to programmatically request the redaction of CDRs (retained for 13 months) held in the Vonage platform. Redact API does not have the capability to redact the server logs (retained for approximately 15 days).
To use the Redact API, you have to provide transaction (message or call) IDs returned in the responses to the API requests sent by you to the Vonage communication APIs. For each ID, you need to make a request to the Vonage Redact API.
It is not possible to make the redaction API request immediately after receiving the transaction ID because it takes time (up to several minutes) for the CDRs to propagate to the long-term storage that Redact API redacts from. Thus, you either have to save the returned transaction (CDR) IDs in your database for later reference or use the Reports API to retrieve the CDRs along with their IDs for your account. More details can be found below.
The scope of redaction of the Redact API depends on what Vonage communication APIs you were using. The detailed description is provided below.
To request access to the Redact API, please visit the Vonage API Support portal.
To learn more about the Redact API please refer to the Vonage Redact API Reference.
Auto-redact Service
Vonage provides a Standard Auto-redact service and Advanced Auto-redact service that automatically redacts personal data from our systems without any actions from your side. Depending on the service that you select, you can define whether you want redaction to be done immediately (only applies to the SMS, Messages, Verify and Number Insight APIs), with a delay of several days (only applies to the standard version). Supported values are 7, 15, 30, 60, and 90 days. The scope of redaction and the configurable delay depends on which of the Vonage communication APIs you are using. Some communication APIs support only Standard Auto-redact while others support Advanced Auto-redact too. Standard Auto-redact cannot redact server logs. It redacts only CDRs but in server logs, personal data is retained for approximately 15 days. Advanced Auto-redact redacts both the CDRs and the server logs. A detailed description is provided in the following paragraphs.
Please find relevant pricing for the Auto-redact service here: Messages API Pricing.
To request activation of the Auto-redact service for your account, please speak to your account manager, or submit a support request and add the required information into the form. The latter will create a ticket with our Support team who will work with the relevant internal teams to enable it for your account. To safeguard our customers, we will conduct an initial review of your business before activating the Auto-redact service on your account. This may require us to reach out to you for additional details.
Auto-redact vs Redact API
| Features | Redact API | Auto-redact Standard | Auto-redact Advanced |
|---|---|---|---|
| Usage | For each record that you want to redact, you need to know a record ID and you need to make a request to the Redact API. | Automatic. Does not require any customer intervention. | Automatic. Does not require any customer intervention. |
| Redaction scope | Only CDRs | Only CDRs | Server logs and CDRs |
| Redaction options | Single request per product | Fixed (all supported products) | Fixed (all supported products) |
| Invocation delay | Can be successfully invoked only after CDR gets propagated to the long-term storage | 7, 15, 30, 60, and 90 days | Immediate |
| Provisioning | Required | Required | Required |
| Supported products | SMS, Number Insight, Messages API*, Voice, Verify, Network APIs**, Vonage QoD | SMS, Number Insight, Messages API*, Voice, Verify, Network APIs**, Vonage QoD | SMS, Number Insight, Messages API*, Verify |
| Price | Free | Paid | Paid |
*Supported channels: SMS, WhatsApp, RCS, Email, Messenger, Viber, MMS
**Includes all existing and future Network APIs
Detailed Description of Redaction Scope per API
SMS API
| Feature | Description |
|---|---|
| Personal data | Personal data includes the message content, the receiver phone number and IP address for outbound messages, and the sender phone number for inbound messages. Personal data is stored in long term storage of CDRs, server logs and data pipeline logs. The SMS API uses a data pipeline software to transport CDRs to various databases. The data pipeline keeps CDRs along with the receiver/sender phone number for 7 days. Personal data stored in longer term storage is held for 13 months as set forth in the table above. Data stored in the server logs is retained for 10 days. |
| Supported Auto-redact type | Advanced or Standard |
| Auto-redact details | Advanced Auto-redact for SMS redacts CDRs, server logs and the data pipeline logs. The scope of auto-redaction includes the following: - Message content - Outbound - Recipient phone number & IP address - Inbound - Sender phone number For immediate redaction, the message content is not written at all, not even to the server logs or the data pipeline logs. The phone number gets encrypted by the SMS API before it gets written to the server logs and the data pipeline logs. When CDRs get propagated to the long-term storage of CDRs, the encrypted number field is automatically redacted along with the IP address. The logs containing encrypted numbers and IP addresses expire on their own. Only a limited number of authorized Vonage engineers have access to the aforementioned decryption keys, which are stored in the Secret Manager. Advanced Auto-redact is exclusively available for messages sent via the Vonage SMS API. For inbound messages received through the Vonage SMS API, customers can use the Standard Auto-redact feature, unless a Business Associate Agreement (BAA) under HIPAA is in place. |
Number Insight API
| Feature | Description |
|---|---|
| Personal data | Personal data includes the phone number and the phone number owner's details: first name, last name, caller name, and subscriber Id. The NI API uses the data pipeline software to transport CDRs to various databases. Personal data is stored in long term storage of CDRs, server logs and data pipeline logs. The data pipeline retains logs with personal data in them for 7 days. Personal data stored in longer term storage is held for 13 months as set forth in the table above. Data stored in the server logs is retained for 13 days. |
| Supported Auto-redact type | Advanced or Standard |
| Auto-redact details | Advanced Auto-redact for NI redacts server logs, CDRs, and the data pipeline logs. The scope of auto-redaction includes the following: - Phone number - Owner’s details redaction When immediate redaction is configured, the content of the redacted fields is not written at all, not even to the server logs or the data pipeline logs. |
Messages API
| Feature | Description |
|---|---|
| Personal data | Personal data includes the message content plus the receiver phone number for outbound messages or sender phone number for inbound messages. Personal data is stored in long term storage of CDRs, server logs and data pipeline logs. The Messages API uses a data pipeline software to transport CDRs to various databases. The data pipeline keeps CDRs along with receiver/sender phone number for 7 days. Personal data stored in longer term storage is held for 13 months as set forth in the table above. Data stored in the server logs is retained for approximately 10 days. |
| Supported Auto-redact type | Advanced or Standard |
| Auto-redact details | Standard Auto-redact for the Messages API redacts only CDRs in the long-term storage of CDRs. The scope of auto-redaction includes the following: - Message content - Outbound - Recipient phone number - Inbound - Sender phone number |
Voice API
When you use the Voice API to make calls, one or more call resources will be created, as well as call detail records (CDRs). While you can use the Auto-redact service or the Redact API to remove personal data (in this case, the phone number) from the CDR, the call resources with telephone numbers will continue to exist.
Call resources are stored as "legs". For instance, if a proxy call is set up between a virtual number V and two other phone numbers A and B, there will be two legs, one between A and V, and one between B and V. These will exist as two separate leg resources with their own unique identifiers.
To determine the identifiers of the leg resources, use the List Legs endpoint and add a query parameter to filter by the conversationUuid of the call.
Once the identifiers are known, each leg resource can be deleted with the Delete Leg endpoint.
For voice applications with call recordings enabled, for example, using the record action of an NCCO, a media resource will be created which holds the recording. This can be deleted using the DELETE method of the Delete a Media Item endpoint.
| Feature | Description |
|---|---|
| Personal data | Personal data includes the receiver phone number for outbound calls and the sender phone number for inbound calls. |
| Supported Auto-redact type | Standard |
| Auto-redact details | Standard Auto-redact for the Voice API redacts only CDRs in the long-term storage of CDRs. The scope of redaction includes the following: - The sender’s phone number - The recipient’s phone number |
Verify API
| Feature | Description |
|---|---|
| Personal data | Personal data includes the phone number or email address and client reference for messages or calls. |
| Supported Auto-redact type | Advanced or Standard |
| Auto-redact details | Standard Auto-redact for the Verify API redacts only CDRs in the long-term storage of CDRs. The scope of redaction includes the following: - The destination phone number or email address - The client reference |
Network APIs
| Feature | Description |
|---|---|
| Personal data | Personal data includes the phone number and IP address. The Network APIs use the data pipeline software to transport CDRs to various databases. Personal data is stored in long term storage of CDRs, server logs and data pipeline logs. The data pipeline retains logs with personal data in them for 14 days. Personal data stored in longer term storage is held for 13 months as set forth in the table above. Data stored in the server logs is retained for 13 days. |
| Supported Auto-redact type | Standard |
| Auto-redact details | The scope of auto-redaction includes the following: - Phone number - IP Address |
Vonage QoD
| Feature | Description |
|---|---|
| Personal data | Personal data includes the phone number and IP address. The Vonage QoD API uses the data pipeline software to transport CDRs to various databases. Personal data is stored in long term storage of CDRs, server logs and data pipeline logs. The data pipeline retains logs with personal data in them for 14 days. Personal data stored in longer term storage is held for 13 months as set forth in the table above. Data stored in the server logs is retained for 13 days. |
| Supported Auto‑redact type | Standard |
| Auto-redact details | The scope of auto-redaction includes the following: - Phone number - IP Address |
Right to Erasure Requests
Under GDPR (and other privacy laws and regulations), individuals have the right to request that a company delete the data that the company retains about them.
If your user sends you a request to have their personal data erased, you may use the Redact API to remove this individual's personal data from all communication records (known as "CDRs") in our system, or purchase the Auto-redact service.
Customer Dashboard
If you need to provide evidence of data redaction, you can do so via the Logs section of the customer dashboard.
In the Vonage Customer Dashboard, it is possible to search for records via a user interface. Generally, searches can be done by going to Log > [selecting the relevant product], and searching:
- Transaction ID, for example, to find details of a single SMS by providing the
message-id. - Phone number and date, for example, to find all SMS sent to a specific phone number on a specific date.
- Date range, for example, to download all messages (up to a limit of 4000) sent between two specific dates.
This method might be appropriate if you need to search one or a few messages sent to a single person as queries are limited to 30 days. For longer time periods you can use the Reports API.
Using the dashboard, you can search for SMS logs, Voice calls, Verify requests, SIM Swap, QoD requests, and Number Insight. You can search by absolute or relative dates.
Reports API
If you need to provide evidence of data redaction, you can do so via the Reports API.
The Reports API can be used to search for all kinds of data records for all types of communication APIs in bulk. It has two relevant modes:
- Retrieve a JSON record describing an individual single message or call. It can be queried using the Load Records Synchronously endpoint.
- Retrieve multiple data records simultaneously. This can be done either by providing a date range to the Load Records Synchronously endpoint or by creating a CSV report containing all records with the help of the Create an Asynchronous Report endpoint.
To learn how to use Reports API please refer to the Reports API Overview.
Technical Support Impact
Please be aware that redaction of data can have a negative impact on our ability to troubleshoot customer-specific service degradations. As part of our commitment to our customers' success, Vonage Support will attempt to provide assistance to all customers wherever possible.
Redaction performed by the Redact API has limited impact on the Vonage Support because we still have access to the unredacted server logs until they expire (expiration time is approximately 15 days). The same applies to the automatic redaction with delay performed by the Auto-redact service. Advanced Auto-redact has the most significant impact on receiving Vonage Support as it is configured to perform immediate redaction so it does not leave any unredacted data sources for Vonage Support to use to troubleshoot.
Typically, Vonage Support diagnoses issues by identifying a specific problematic API call or a communication event relating to the issue, or a pattern of related events (messages or calls). Vonage Support must often identify the data records related to the issue using the date of the issue and a phone number or a message text/body. Examples could include:
- The
tophone number for an outbound SMS to the phone of one of your users. - The
fromphone number for an inbound call to your Vonage virtual number.
If you enable immediate number redaction, Vonage Support will not be able to help support you with just the phone number and the time window. Without having phone numbers in our data records and logs, Vonage Support will not be able to use differential analysis and compare failed and successful transactions over time (patterns) to a single number or a range of numbers. Instead, you will need to provide the relevant transaction IDs that were given to you in the API responses. For example, for SMS, this is the message-id value. If your system does not log/store the responses you receive from the Vonage APIs or it is difficult to access this response data, you should use either the Reports API or the Customer Dashboard to view your transactional data records in our system, find those related to the issue, and share their IDs with us to troubleshoot.
With the IDs, Vonage Support may identify the problem immediately, but in some cases it may take considerable time. For example, if the immediate Advanced auto-redaction is enabled for SMS and if a Telecommunications Service Provider rejects the SMS because of some local regulations on the contents of the message or some unicode encoding issues, then without knowing the message body, Vonage Support will not be able to pinpoint the problem immediately and may even need to involve the Telecommunications Service Provider in the troubleshooting process.
Note that all transactional data records are deleted after 13 months, so we will not be able to help you diagnose an issue with a transaction after expiration of this time period.