Security
Enterprise-grade security, by default.
Your conversations contain sensitive customer data. We protect it with independent audits, strong encryption and strict access controls.
How we protect your data
TLS 1.3 in transit and AES-256 at rest, with per-workspace keys.
SAML SSO, SCIM provisioning, role-based permissions and full audit logs.
Card numbers, SSNs and other sensitive fields are redacted from transcripts and audio.
Choose US or EU storage and set retention from 1 to 365 days.
Isolated tenants on hardened cloud infrastructure with 24/7 monitoring.
Your data is never used to train shared models.
Certifications and compliance
Independent annual audit of security, availability and confidentiality controls.
Certified information security management system across all environments.
Business Associate Agreements for healthcare customers on Enterprise plans.
Data Processing Agreement, EU data residency and full data-subject rights support.
Card data is captured through a certified payment flow and never reaches the model.
Built-in consent capture, recording disclosures and do-not-call handling.
AI safety and guardrails
Define topics the agent must never discuss, with automatic escalation when they come up.
Agents answer only from approved knowledge sources and say so when they don't know.
Configurable triggers hand the conversation to a person with a full summary.
Every answer is logged with the sources it used, so you can review any decision.
Security practices
Third-party penetration tests every year, plus continuous automated scanning.
A private bug bounty programme rewards researchers who report vulnerabilities.
Background checks, security training and least-privilege access for every employee.
A documented, tested incident response plan with customer notification within 72 hours.
Encrypted backups every hour with a tested disaster-recovery plan.
Every sub-processor is reviewed for security and listed publicly.
Documents available on request
Security FAQ
No. Your conversations and knowledge sources are never used to train shared models. Fine-tuned models are private to your workspace.
In the region you choose — US, EU or APAC. Data does not leave that region.
You set the retention period, from 0 days to 7 years. Deleted data is purged from backups within 30 days.
Yes. SAML SSO, SCIM provisioning and enforced 2FA are available on Business and Enterprise plans.
Found a vulnerability? Email security@onevox.ai. We respond within 48 hours.