Security
We process sensitive call recordings. Security is a product requirement.
Voicemarrow handles recordings from regulated industries including financial services, insurance, and healthcare. Data security is not a compliance checkbox for us. It is part of how the product is built.
Data Protection
How your call data is protected
Encryption at Rest
All call recordings, transcripts, and score data are encrypted at rest using AES-256. Encryption keys are managed per customer and rotated on a defined schedule. No plain-text data is written to disk.
TLS 1.3 in Transit
All API communications, recording transfers, and dashboard traffic are encrypted in transit using TLS 1.3. Older protocol versions are disabled. Certificate pinning is enforced for native telephony connectors.
Audit Logs
Every access event, score query, export, and configuration change is written to an immutable audit log. Logs are accessible via the API and exportable for compliance review. Enterprise plans include extended log retention.
Data Retention Controls
Customers control how long recordings and transcripts are retained in Voicemarrow. Deletion is immediate and verifiable. We do not retain data beyond the configured retention window for any reason.
Role-Based Access
Access to score data, recordings, and coaching briefs is controlled by role. Agents see only their own data. Supervisors see their team. QA managers see cross-team reporting. Admin roles are separately scoped.
Data Processing Agreements
We provide standard data processing agreements (DPA) for all plans. Enterprise customers can request addenda for specific regulatory requirements or jurisdiction-specific clauses. Contact us to start the DPA process.
Regulated Industries
Built for the industries with the most sensitive calls
Financial services calls include account numbers, social security numbers, and payment information. Insurance calls contain health and claims data. Healthcare calls involve protected health information under HIPAA.
Voicemarrow processes these calls. We take that seriously. Our architecture is designed with the assumption that every recording is sensitive, not as an edge case.
For questions about specific compliance requirements, data residency, or security documentation, contact us directly.
Contact us about securitySecurity Snapshot
Security questions? We will answer them directly.
If you have specific requirements around data residency, HIPAA, FINRA, or other regulatory frameworks, contact us and we will walk through what Voicemarrow supports.