Progressive
  • The Problem
  • Solution
  • Enterprise
  • Results
  • FAQ's
  • See the Platform
See the Platform

Draft — pending review. This overview is a placeholder describing intended practices. It should be reviewed and validated against Voxlytics' actual infrastructure and controls before being published as a compliance or procurement reference, and revisited once the company is incorporated and enterprise customers require a formal Data Processing Agreement (DPA).

Security & Data Processing Overview

Last updated: September 19, 2026

This page summarizes how Voxlytics approaches security and the processing of customer and call data across the platform (voxlytics.ai and app.voxlytics.ai). It is intended as a general overview; enterprise customers with specific compliance requirements should contact us to discuss a formal Data Processing Agreement.

1. Roles: Controller & Processor

For call data collected on behalf of a customer running outbound campaigns, the customer acts as the data controller and Voxlytics acts as a data processor, processing that data only to provide the Service and per the customer's instructions.

2. Infrastructure & Hosting

The application and its data are hosted on reputable cloud infrastructure providers. Telephony and call routing are handled via SIP trunking and WebRTC infrastructure. Access to production systems is limited to authorized personnel.

3. Encryption

We aim to encrypt data in transit using industry-standard protocols (e.g. TLS) and to encrypt sensitive data at rest where supported by our infrastructure providers.

4. Access Controls

Access to customer data within the platform is scoped by account and role — agents, supervisors, and administrators see only the data relevant to their role and organization. Internal access to production data is restricted and logged.

5. Call Recording & AI Processing

Where call recording is enabled, recordings and derived transcripts/insights are associated with the originating customer account and are not shared across customer organizations. AI-based transcription and analysis may be performed by third-party AI service providers under confidentiality and data-handling terms.

6. Sub-processors

We rely on select third-party providers for hosting, telephony/SIP trunking, and AI transcription/analysis. A current list of sub-processors is available on request athi@voxlytics.ai.

7. Data Retention & Deletion

Customer data, including call recordings and transcripts, is retained per the retention settings on a customer's account and our Privacy Policy. Customers may request deletion of their data by contacting us.

8. Incident Response

In the event of a security incident affecting customer data, we intend to notify affected customers without undue delay and to take reasonable steps to investigate and remediate the issue, consistent with applicable law.

9. Compliance Roadmap

Voxlytics is an early-stage product. Formal certifications (e.g. SOC 2, ISO 27001) and a signed Data Processing Agreement are not yet in place but are on the roadmap as the company formalizes its legal entity and enterprise customer base grows.

10. Contact Us

For security questions, vulnerability reports, or DPA requests, contacthi@voxlytics.ai.

The ProblemSolutionEnterprise
ResultsFAQ'sPrivacy
TermsCookiesSecurity