Trust Center
Security you can inspect
VoicaX was architected as a multi-tenant enterprise platform from day one. Governance, isolation, and audit are core primitives — not bolted-on features.
Encryption
TLS 1.2+ in transit. AES-256-GCM for provider credentials at rest. Managed keys rotate on a scheduled cadence.
RBAC
Role- and permission-based access is evaluated on every server request. No client-side authorization.
Multi-tenancy
PostgreSQL row-level security enforces tenant boundaries at the database layer, independent of application code.
Audit Logging
Every mutation across auth, billing, admin, and platform APIs is logged with actor, target, and diff.
Data Protection
Least-privilege access to production. Secrets stored in an encrypted vault. Vendor access is scoped and reviewed.
Backups
Automated managed backups with point-in-time recovery. Restore drills scheduled quarterly. (Program placeholder — details on request.)
Incident Response
Documented playbooks for detection, containment, notification, and post-incident review. Customer notification without undue delay.
API Security
Hashed API keys, signed webhooks, and per-key scoped permissions with rotation.
Data Ownership
Your data is yours. Full export via API and portable formats — no lock-in.
Compliance
Roadmap, not marketing claims
We publish the status of each framework honestly. Where we're aligned but not certified, we say so.
GDPR
Processor role, DPA available, SCCs where applicable.
SOC 2 Type II
Controls implementation in progress. Attestation targeted after initial customer cohort.
ISO 27001
Program design underway; certification targeted post-SOC 2.
HIPAA-aligned
BAA and additional safeguards for eligible enterprise deployments.
VoicaX does not claim certifications it has not earned. Contact us for current attestation status and evidence packets.
Need a security review?
We walk security and procurement teams through our architecture and share our current evidence.
