VoxLink.ai

Enterprise-Grade Security

Security & Compliance

Protecting customer and business data should be built into every layer of an AI communications platform. VoxLink combines secure infrastructure, privacy controls and operational safeguards designed for business-critical voice automation.

Information Security

A documented approach to governance, access, encryption and incident handling across the platform.

Quality & Operational Controls

Change management, review steps and operational routines that keep agent behaviour predictable.

Privacy

Workspace-scoped data, configurable retention and clear handling of recordings and transcripts.

Healthcare Security

We assess healthcare privacy and security requirements with your team before deployment.

ISO 27001:2022

Information Security Management System

ISO 9001:2015

Quality Management System

GDPR Compliant

EU & US Data Routing Options

HIPAA Available

Enterprise Healthcare Compliance

Certifications issued by SYSTEMA CERTIFICARI SRL - IAS accredited (MSCB-173), IAF recognised

Programme

Information Security Management

Our security programme is documented against recognised information-security practices, covering governance, access, cryptography, incident management, continuity and auditability - so your reviewers can see how decisions are made, not just what the product does.

01

Risk Management

Identify the risks that matter to voice automation - data exposure, misrouting, integration access - and record how each is treated.

02

Access Control

Role-based access for workspace members, least-privilege integration credentials and removal of access when roles change.

03

Cryptography

Data is encrypted in transit and at rest by the platform and its hosting providers. Specific protocol versions are confirmed in writing on request.

04

Incident Response

Defined ownership, triage steps and customer communication paths so security events are handled consistently, not improvised.

05

Business Continuity

Backup and recovery routines for workspace data, with restoration expectations documented for your review.

06

Audit & Compliance

Configuration changes, call records and integration activity are traceable so your team can evidence what happened and when.

Educational

ISO 27001 vs SOC 2

Buyers often ask for both, but they answer different questions. One certifies a management system; the other reports on how controls operated. Neither replaces the other, and the right ask depends on your review process.

What it is

ISO 27001
Certification of a management system - how security is governed and continually improved.
SOC 2
An attestation report from an independent auditor describing controls and how they operated.

Recognition

ISO 27001
An international standard, widely referenced in Europe, Asia-Pacific and global procurement.
SOC 2
Most commonly requested by North American buyers and enterprise vendor-review teams.

Assessment

ISO 27001
Accredited certification body audit, with surveillance audits across the certification cycle.
SOC 2
Type I reviews design at a point in time; Type II tests operation across a review period.

Scope

ISO 27001
The organisation defines the scope of the management system and states it on the certificate.
SOC 2
Scope is set by the trust services criteria selected, such as security, availability or confidentiality.

Controls

ISO 27001
Controls are selected and justified against the standard's control set and the risk assessment.
SOC 2
Controls are described by the organisation and then tested by the auditor.

Ongoing assurance

ISO 27001
Maintained through recertification and surveillance activity.
SOC 2
Maintained by producing a new report for each review period.

This comparison is provided for evaluation purposes only and is not a statement that VoxLink holds either certification or report.

Privacy

Privacy Controls Built Into the Product

Call data belongs to your business. Retention, residency, processing terms and individual rights are settled with your team before launch rather than left to assumption.

Configurable Data Retention

Retention preferences for recordings, transcripts and call records are agreed with your team and applied to your workspace. Confirm the exact retention settings available for your plan before you go live.

Data Residency

Region availability depends on your deployment and hosting configuration. Tell us the regions your organisation requires and we will confirm what is supported for your workspace.

Data Processing Agreement

Where your organisation requires a data processing agreement, our team will review your template or provide terms covering processing purpose, security obligations and handling instructions.

Data Subject Rights

Requests for access, correction, export or deletion of personal data held in your workspace are handled with your team through a documented request path.

Healthcare

Healthcare Security for Enterprise

Healthcare deployments carry obligations that depend on your jurisdiction, systems and the information your agent handles. Contact us to assess healthcare privacy and security requirements for your deployment.

Access controls & encryption

Workspace-scoped access with encryption in transit and at rest applied to call data.

Audit logging

Traceable records of configuration changes and call activity for internal review.

Incident workflows

Defined escalation and notification paths agreed with your organisation.

Risk assessment

A joint review of where patient information would be captured, stored and shared.

Retention

Retention and deletion expectations set against your clinical record-keeping policies.

Agreements

Any business associate or equivalent agreement is assessed case by case before deployment.

Platform

Infrastructure Security

The safeguards that sit underneath every call, transcript and integration event.

Encryption

Call audio, transcripts and workspace data are encrypted in transit and at rest. Protocol detail is confirmed in writing for security reviews.

Access Control

Least-privilege administrative access, role-based workspace permissions and scoped integration credentials.

Monitoring & Detection

Platform and application monitoring with alerting on abnormal call, authentication and integration activity.

Business Continuity

Backups of workspace configuration and call records, with recovery steps documented for your review.

Incident Response

A single owner per incident, defined triage stages and a customer communication path.

Vendor Security

Hosting, telephony and model providers are reviewed before use, and the current list is shared under review.

Vendor review

What to evaluate in an AI voice vendor

Rather than tick-boxes, use this matrix to ask the same questions of every vendor - including us - and to record the evidence you were given.

ISO 27001

Ask: Is the security programme documented against the standard, and what is the current assessment status?

Evidence: Certificate with scope and issuing body, or a written statement of current status.

SOC 2

Ask: Is a report available, and is it Type I or Type II?

Evidence: Report under NDA, including the review period and criteria covered.

Privacy / GDPR controls

Ask: How is personal data captured, minimised and deleted?

Evidence: Privacy documentation, retention settings and deletion request path.

Healthcare requirements

Ask: Which safeguards apply, and is an agreement available?

Evidence: Documented safeguard review and any signed agreement.

Regional data routing

Ask: Which regions can process and store call data?

Evidence: Written confirmation of the regions available for your deployment.

Data processing agreement

Ask: Can the vendor sign your DPA or provide equivalent terms?

Evidence: Executed DPA or the vendor's processing terms.

Retention controls

Ask: Can retention be configured per data type?

Evidence: Configuration walkthrough plus written confirmation of applied settings.

Audit evidence

Ask: What activity can be reconstructed after the fact?

Evidence: Sample audit records, call logs and change history.

Documentation

Security Documentation

We share documentation that exists and belongs to VoxLink. Anything not yet available is stated plainly rather than implied.

Certificates

Any current certification documents for the VoxLink legal entity are provided directly when available.

Request access

Data processing agreement

Processing terms, or a review of your own template, shared through our team.

Request access

Subprocessor list

The current list of hosting, telephony and model providers, shared on request.

Request access

Security questionnaire

We complete your standard questionnaire and provide written answers for your file.

Request access

Architecture & security overview

A written description of the platform, data paths and safeguards for your review.

Request access

FAQ

Security questions, answered honestly

Related

Secure AI communications, built for business.

Review VoxLink’s security controls, deployment options and data-handling requirements with our team before you go live.