I’ve tackled this before with HIPAA setups, the workaround is to use a secure middleware that authenticates VAPI webhooks and then forwards recordings into your whitelisted storage. That way you don’t need static IPs directly from VAPI. Curious, which storage provider are you using? Happy to chat through the setup if you’d like to connect. @peoplekind