Security you can check, not just trust.
How VoisX protects your conversations, credentials and customer data, written as specific commitments, not slogans.
Security commitments
Data residency
Each organisation chooses India or UAE. Calls, transcripts and recordings are stored in that region.
Secrets in a vault
API keys and connector credentials live in a dedicated secrets vault, never in application config.
Tenant isolation
Organisations and projects are isolated from each other across data and integrations.
Recording is opt-in
Call recording is off by default. When you turn it on, recordings follow the retention period you set.
Role-based access
Owners, admins and members get only the permissions their role allows.
Audit log
Administrative actions are recorded, so you can see who changed what, and when.
Compliance
Where we stand today.
We only list what is true today, and we won’t show a certification until we hold it. Ask us for our current status on any framework.
| Framework | Status |
|---|---|
| UAE PDPL | Contact us for our current status |
| India DPDP Act | Contact us for our current status |
| GDPR | Contact us for our current status |
| SOC 2 Type II | Not yet certified |
| ISO/IEC 27001 | Not yet certified |
Subprocessors
The providers that process data on our behalf. Your data is hosted in the region your organisation chooses, India or UAE.
- Voice and language models
OpenAI
Gemini
ElevenLabs- Phone carriers
Twilio
Plivo
For the full list, including hosting providers and the region each one runs in, contact us.
Report a vulnerability
Found a security issue in VoisX? Tell us through our contact page with enough detail to reproduce it, and please give us a chance to fix it before you disclose it publicly.
