Security

We process sensitive call recordings. Security is a product requirement.

Voicemarrow handles recordings from regulated industries including financial services, insurance, and healthcare. Data security is not a compliance checkbox for us. It is part of how the product is built.

Data Protection

How your call data is protected

Encryption at Rest

All call recordings, transcripts, and score data are encrypted at rest using AES-256. Encryption keys are managed per customer and rotated on a defined schedule. No plain-text data is written to disk.

TLS 1.3 in Transit

All API communications, recording transfers, and dashboard traffic are encrypted in transit using TLS 1.3. Older protocol versions are disabled. Certificate pinning is enforced for native telephony connectors.

Audit Logs

Every access event, score query, export, and configuration change is written to an immutable audit log. Logs are accessible via the API and exportable for compliance review. Enterprise plans include extended log retention.

Data Retention Controls

Customers control how long recordings and transcripts are retained in Voicemarrow. Deletion is immediate and verifiable. We do not retain data beyond the configured retention window for any reason.

Role-Based Access

Access to score data, recordings, and coaching briefs is controlled by role. Agents see only their own data. Supervisors see their team. QA managers see cross-team reporting. Admin roles are separately scoped.

Data Processing Agreements

We provide standard data processing agreements (DPA) for all plans. Enterprise customers can request addenda for specific regulatory requirements or jurisdiction-specific clauses. Contact us to start the DPA process.

Regulated Industries

Built for the industries with the most sensitive calls

Financial services calls include account numbers, social security numbers, and payment information. Insurance calls contain health and claims data. Healthcare calls involve protected health information under HIPAA.

Voicemarrow processes these calls. We take that seriously. Our architecture is designed with the assumption that every recording is sensitive, not as an edge case.

For questions about specific compliance requirements, data residency, or security documentation, contact us directly.

Contact us about security

Security Snapshot

Encryption at rest AES-256
Encryption in transit TLS 1.3
Audit log retention 1 year (Enterprise: custom)
Data processing agreement Available on all plans
Data residency (Enterprise) US, EU options

Security questions? We will answer them directly.

If you have specific requirements around data residency, HIPAA, FINRA, or other regulatory frameworks, contact us and we will walk through what Voicemarrow supports.