How we protect you

Nine things we get right by default.

Data protection

Your customer data is encrypted at rest with AES-256 and in transit with TLS 1.3. We separate customer data by workspace at the database level. No shared tables, no leak risk.

Encryption everywhere

Every byte we store is encrypted. Every connection is encrypted. Call recordings are encrypted and only decrypted for playback to authorized users.

GDPR-conscious, by design

We're not yet fully GDPR-compliant — we're working toward it. Opt-in tracking, right to erasure, data portability are in place; SOC 2 / ISO 27001 are on the roadmap, not the badge.

Full audit log

Every action, every actor, every record. Who changed what, when, and why. Exportable, queryable, never deleted. Available for any timeframe on Scale plans.

EU infrastructure

Your data lives in EU data centers (Frankfurt, Amsterdam). Backups never leave the EU. No US transfers without your explicit configuration.

Access control

Role-based permissions, fine-grained record access, optional SSO with SAML 2.0. Hide sensitive fields from team members who don't need them.

Incident response

A documented response process and 24/7 on-call rotation. We notify affected customers within 24 hours of any confirmed incident — required by law, and by our values.

Data residency choice

Choose where your data lives — EU (default), UK, or US. Once chosen, it never moves without your written consent.

Vendor management

Every subprocessor (OpenAI, Twilio, AWS, etc.) is vetted, listed publicly, and bound by data processing agreements. Updates to our subprocessor list are notified in advance.

Our approach to AI safety.

An AI that calls your customers is a powerful tool. Used carelessly, it could embarrass your business, damage trust, or get you in legal trouble. So we built Voxera with the assumption that AI mistakes are inevitable — and the human stays in control.

Every change Voxera proposes is reviewable. Every call is recorded and transcribed. Every report comes from real data, not from a language model guessing at the answer. If something goes wrong, you'll know immediately, you'll know why, and you can roll it back in one click.

We don't believe in "AI that runs itself." We believe in AI that does the work, and people who decide what's worth doing.

The compliance program.

For regulated industries — healthcare-adjacent services, financial services, and other sensitive spaces — Voxera offers configurable compliance controls on the Scale plan. You set the rules. Voxera enforces them at the call level, the record level, and the report level.

  • Required disclosures at the start of every call
  • Configurable do-not-discuss topics with auto-escalation
  • Calling hours that respect regional law
  • Opt-in capture and proof of consent on every interaction
  • Data retention periods aligned to your sector's requirements
  • Configurable redaction of sensitive fields in transcripts

Need something specific? Email security@usevoxera.com — it goes to the founders, not a ticket queue.

Trust, by design.

Want to talk to our security team? We'll send the full documentation.

Request documentation
Private beta · invite-only · no card required