How we secure the voice data you trust us with. Audited controls, EU-only hosting, transparent sub-processors — and every customer can verify each control themselves.
Every item below is in production today. Each links to where to verify it — your data, your audit.
All PII tables (calls, leads, organizations, users, agents, recordings) have ENABLE ROW LEVEL SECURITY with org-membership policies. Cross-org reads only possible via signed service-role on the backend.
Every admin action, impersonation, and PII access is written to audit_logs with prevent_audit_update + prevent_audit_delete Postgres rules — append-only by design.
Self-service via /preferences/privacy in the dashboard OR vocito.ai/forget-me for non-customers (HMAC-signed email confirmation). Deletes propagate to Twilio recordings and ElevenLabs agents.
30 / 90 / 180 / 365 days per organisation. A daily 03:00 UTC cron purges transcripts, anonymises lead names, and deletes Twilio recordings past the retention window.
The security_incidents table feeds a 30-minute cron that pages the DPO mailbox until notified_at is set. Internal runbook documents containment + 72-hour AP notification.
Every customer agent has a per-language recording disclaimer in its first_message — the backend rejects any custom greeting that omits it. No "silent recording" surprises.
For enterprise customers and high-sensitivity niches (legal, healthcare, financial), transcripts can be AES-256-GCM encrypted at the application layer with a key only the backend holds.
For callers from DE / AT / CH / PL, an optional pre-call DTMF prompt asks for explicit consent before the recording starts. Toggleable per organisation.
Full list published with regions, role, and safeguards. Customers are notified 30 days before any new sub-processor goes live (Art. 28.3) via automated email.
What's actively being added in 2026.
| Control | Status | Target |
|---|---|---|
| SOC 2 Type 1 readiness assessment | Preparing evidence | Q3 2026 |
| ISO 27001 gap analysis | Scoping | Q4 2026 |
| Per-region data hosting (US option) | Design phase | Q4 2026 |
| Customer-side webhook signature verification (HMAC-SHA256) | In progress | Q3 2026 |
| Bug bounty programme | Sourcing platform | Q4 2026 |
If you've found a security issue, please email security@vocito.ai — we aim to acknowledge within one business day. Coordinated disclosure preferred. We don't currently pay bounties but will publicly credit responsible reporters in this page's footer.
Enterprise & regulated customers can request signed agreements.
Contact security@vocito.ai