Skip to content
Back

Security

Enterprise-grade security, by default.

Your conversations contain sensitive customer data. We protect it with independent audits, strong encryption and strict access controls.

SOC 2
Type II audited annually
GDPR
DPA available on request
HIPAA
BAA on Enterprise plans
AES-256
Encryption at rest

How we protect your data

Encryption

TLS 1.3 in transit and AES-256 at rest, with per-workspace keys.

Access control

SAML SSO, SCIM provisioning, role-based permissions and full audit logs.

PII redaction

Card numbers, SSNs and other sensitive fields are redacted from transcripts and audio.

Data residency

Choose US or EU storage and set retention from 1 to 365 days.

Infrastructure

Isolated tenants on hardened cloud infrastructure with 24/7 monitoring.

Model privacy

Your data is never used to train shared models.

Certifications and compliance

SOC 2 Type II

Independent annual audit of security, availability and confidentiality controls.

ISO 27001

Certified information security management system across all environments.

HIPAA

Business Associate Agreements for healthcare customers on Enterprise plans.

GDPR and CCPA

Data Processing Agreement, EU data residency and full data-subject rights support.

PCI DSS

Card data is captured through a certified payment flow and never reaches the model.

TCPA and call consent

Built-in consent capture, recording disclosures and do-not-call handling.

99.99%
Uptime over the last 12 months
3
Regions with isolated data (US, EU, APAC)
<48 hrs
Security response time
24/7
Security monitoring

AI safety and guardrails

Prohibited topics

Define topics the agent must never discuss, with automatic escalation when they come up.

Grounded answers

Agents answer only from approved knowledge sources and say so when they don't know.

Human handoff

Configurable triggers hand the conversation to a person with a full summary.

Full audit trail

Every answer is logged with the sources it used, so you can review any decision.

Security practices

Penetration testing

Third-party penetration tests every year, plus continuous automated scanning.

Bug bounty

A private bug bounty programme rewards researchers who report vulnerabilities.

Employee security

Background checks, security training and least-privilege access for every employee.

Incident response

A documented, tested incident response plan with customer notification within 72 hours.

Backups and recovery

Encrypted backups every hour with a tested disaster-recovery plan.

Vendor review

Every sub-processor is reviewed for security and listed publicly.

Documents available on request

✓ SOC 2 Type II report✓ ISO 27001 certificate✓ Penetration test summary✓ Data Processing Agreement✓ Sub-processor list✓ Security questionnaire (CAIQ)✓ HIPAA BAA template

Security FAQ

Do you train models on our data?+

No. Your conversations and knowledge sources are never used to train shared models. Fine-tuned models are private to your workspace.

Where is our data stored?+

In the region you choose — US, EU or APAC. Data does not leave that region.

How long do you keep recordings?+

You set the retention period, from 0 days to 7 years. Deleted data is purged from backups within 30 days.

Can we use single sign-on?+

Yes. SAML SSO, SCIM provisioning and enforced 2FA are available on Business and Enterprise plans.

Responsible disclosure

Found a vulnerability? Email security@onevox.ai. We respond within 48 hours.