Encrypted in transit and at rest. Hosted in the region your customers live in — AU and UK live today, EU and US as you land there. Audit-ready from day one. Written by people who actually read the controls.
Less a poster, more a checklist. Here's the shape of our security programme.
Data is encrypted end-to-end, with customer-managed keys available on Scale.
Your data doesn't leave the region you pick, full stop.
Who sees what, and proof of who saw what.
Sensitive data is redacted from transcripts and kept off downstream logs.
We watch the platform so you don't have to — and we tell you when something happens.
A small, audited set of sub-processors. You can see all of them.
SIP/SRTP from your carrier terminates at our region-local Session Border Controller.
Audio is streamed through our containerised pipeline — STT, LLM, TTS, tools — all in-region.
Every outbound integration call is HMAC-signed with per-tenant keys, from known IPs.
Audio + transcripts encrypted with your CMK. Retention set by your policy, not ours.
ap-southeast-2 for AU tenants, eu-west-2 for UK tenants, and so on. No cross-region replication, no "convenience copies," no third-party training.Found something? We pay for it. Our bug-bounty programme covers authentication bypass, data exposure, injection, and call-takeover vulnerabilities. Report to security@voxapp.com with our PGP key.
Safe-harbour policy for good-faith research. Typical first-response within 4 business hours, 24 / 7.
We built this for the people who have to sign the DPA. Questionnaires answered in a day, not a quarter.