Your meeting data is sensitive. VoxeNova is built from the ground up with dedicated infrastructure, encryption at every layer, and strict access controls to keep your data safe.
LUKS full-disk encryption on every customer instance. Per-customer unique encryption keys managed via Fernet-encrypted secrets delivery.
Dedicated VM per customer with separate database, Redis instance, and firewall rules. No shared infrastructure between tenants.
EU data residency by default (Germany or Finland). US and Asia-Pacific regions available on enterprise request. Data stays in your selected region.
Tiered access model (3 levels), SSH certificate authentication, and dual authorization required for any direct data access.
Append-only audit logging with actor fingerprinting. Every administrative action is recorded with timestamp, actor, and context.
Multi-factor authentication required for all administrative access. TOTP-based MFA with role-based access control.
VoxeNova does not persist call audio. The inbound voice stream and the AI facilitator's spoken responses both pass through memory only — we transcribe in real time, then drop the bytes. Transcripts (text) follow your retention policy.
Cloudflare WAF and DDoS protection in front of every instance. Firewall rules restrict all traffic to Cloudflare IP ranges only — no direct server access from the public internet.
TLS 1.2+ enforced on all connections. SSH Certificate Authority authentication (no passwords). All internal service communication encrypted in transit.
LUKS-encrypted volumes on every instance. Per-customer unique secrets delivered via Fernet-encrypted blobs. Database credentials isolated with .pgpass per instance.
All AI processing runs via AWS Bedrock (SOC 2, ISO 27001 compliant). Meeting data stays in the selected data region. No training on customer data.
GDPR-ready with configurable data retention, deletion tracking, and DPA acceptance fields. Full data subject rights support (access, rectification, erasure, portability).
We are transparent about every third-party service that processes your data.
| Processor | Purpose | Compliance |
|---|---|---|
| Stripe | Payment processing | PCI DSS Level 1 |
| AWS Bedrock | AI processing | SOC 2, ISO 27001 |
| Recall.ai | Meeting bot | SOC 2 |
| Deepgram | Speech-to-text | SOC 2 |
| Cartesia | Text-to-speech | SOC 2 |
| Hetzner Cloud | Infrastructure | ISO 27001 |
We are happy to discuss our security practices in detail, provide additional documentation, or schedule a security review call with your team.