Information Security
A documented approach to governance, access, encryption and incident handling across the platform.
Enterprise-Grade Security
Protecting customer and business data should be built into every layer of an AI communications platform. VoxLink combines secure infrastructure, privacy controls and operational safeguards designed for business-critical voice automation.
A documented approach to governance, access, encryption and incident handling across the platform.
Change management, review steps and operational routines that keep agent behaviour predictable.
Workspace-scoped data, configurable retention and clear handling of recordings and transcripts.
We assess healthcare privacy and security requirements with your team before deployment.
ISO 27001:2022
Information Security Management System
ISO 9001:2015
Quality Management System
GDPR Compliant
EU & US Data Routing Options
HIPAA Available
Enterprise Healthcare Compliance
Certifications issued by SYSTEMA CERTIFICARI SRL - IAS accredited (MSCB-173), IAF recognised
Programme
Our security programme is documented against recognised information-security practices, covering governance, access, cryptography, incident management, continuity and auditability - so your reviewers can see how decisions are made, not just what the product does.
Identify the risks that matter to voice automation - data exposure, misrouting, integration access - and record how each is treated.
Role-based access for workspace members, least-privilege integration credentials and removal of access when roles change.
Data is encrypted in transit and at rest by the platform and its hosting providers. Specific protocol versions are confirmed in writing on request.
Defined ownership, triage steps and customer communication paths so security events are handled consistently, not improvised.
Backup and recovery routines for workspace data, with restoration expectations documented for your review.
Configuration changes, call records and integration activity are traceable so your team can evidence what happened and when.
Educational
Buyers often ask for both, but they answer different questions. One certifies a management system; the other reports on how controls operated. Neither replaces the other, and the right ask depends on your review process.
This comparison is provided for evaluation purposes only and is not a statement that VoxLink holds either certification or report.
Privacy
Call data belongs to your business. Retention, residency, processing terms and individual rights are settled with your team before launch rather than left to assumption.
Retention preferences for recordings, transcripts and call records are agreed with your team and applied to your workspace. Confirm the exact retention settings available for your plan before you go live.
Region availability depends on your deployment and hosting configuration. Tell us the regions your organisation requires and we will confirm what is supported for your workspace.
Where your organisation requires a data processing agreement, our team will review your template or provide terms covering processing purpose, security obligations and handling instructions.
Requests for access, correction, export or deletion of personal data held in your workspace are handled with your team through a documented request path.
Healthcare
Healthcare deployments carry obligations that depend on your jurisdiction, systems and the information your agent handles. Contact us to assess healthcare privacy and security requirements for your deployment.
Workspace-scoped access with encryption in transit and at rest applied to call data.
Traceable records of configuration changes and call activity for internal review.
Defined escalation and notification paths agreed with your organisation.
A joint review of where patient information would be captured, stored and shared.
Retention and deletion expectations set against your clinical record-keeping policies.
Any business associate or equivalent agreement is assessed case by case before deployment.
Platform
The safeguards that sit underneath every call, transcript and integration event.
Call audio, transcripts and workspace data are encrypted in transit and at rest. Protocol detail is confirmed in writing for security reviews.
Least-privilege administrative access, role-based workspace permissions and scoped integration credentials.
Platform and application monitoring with alerting on abnormal call, authentication and integration activity.
Backups of workspace configuration and call records, with recovery steps documented for your review.
A single owner per incident, defined triage stages and a customer communication path.
Hosting, telephony and model providers are reviewed before use, and the current list is shared under review.
Vendor review
Rather than tick-boxes, use this matrix to ask the same questions of every vendor - including us - and to record the evidence you were given.
| Area | What to ask | Evidence to request |
|---|---|---|
| ISO 27001 | Is the security programme documented against the standard, and what is the current assessment status? | Certificate with scope and issuing body, or a written statement of current status. |
| SOC 2 | Is a report available, and is it Type I or Type II? | Report under NDA, including the review period and criteria covered. |
| Privacy / GDPR controls | How is personal data captured, minimised and deleted? | Privacy documentation, retention settings and deletion request path. |
| Healthcare requirements | Which safeguards apply, and is an agreement available? | Documented safeguard review and any signed agreement. |
| Regional data routing | Which regions can process and store call data? | Written confirmation of the regions available for your deployment. |
| Data processing agreement | Can the vendor sign your DPA or provide equivalent terms? | Executed DPA or the vendor's processing terms. |
| Retention controls | Can retention be configured per data type? | Configuration walkthrough plus written confirmation of applied settings. |
| Audit evidence | What activity can be reconstructed after the fact? | Sample audit records, call logs and change history. |
Ask: Is the security programme documented against the standard, and what is the current assessment status?
Evidence: Certificate with scope and issuing body, or a written statement of current status.
Ask: Is a report available, and is it Type I or Type II?
Evidence: Report under NDA, including the review period and criteria covered.
Ask: How is personal data captured, minimised and deleted?
Evidence: Privacy documentation, retention settings and deletion request path.
Ask: Which safeguards apply, and is an agreement available?
Evidence: Documented safeguard review and any signed agreement.
Ask: Which regions can process and store call data?
Evidence: Written confirmation of the regions available for your deployment.
Ask: Can the vendor sign your DPA or provide equivalent terms?
Evidence: Executed DPA or the vendor's processing terms.
Ask: Can retention be configured per data type?
Evidence: Configuration walkthrough plus written confirmation of applied settings.
Ask: What activity can be reconstructed after the fact?
Evidence: Sample audit records, call logs and change history.
Documentation
We share documentation that exists and belongs to VoxLink. Anything not yet available is stated plainly rather than implied.
Any current certification documents for the VoxLink legal entity are provided directly when available.
Request accessProcessing terms, or a review of your own template, shared through our team.
Request accessThe current list of hosting, telephony and model providers, shared on request.
Request accessWe complete your standard questionnaire and provide written answers for your file.
Request accessA written description of the platform, data paths and safeguards for your review.
Request accessFAQ
Related
Review VoxLink’s security controls, deployment options and data-handling requirements with our team before you go live.