Security
The controls that are implemented, and the assurance that is outstanding.
Who this is for
Security reviewers and administrators.
No screenshot on this pageA control is not a screen. Tenant isolation lives in a SQL predicate and session revocation in a code path, and photographing a settings page would show a surface rather than the control. The Trust Center publishes each claim with its real verification state.
Tenant isolation
Every tenant-scoped query filters by organization inside the SQL predicate, not as a filter applied afterwards. A request for another tenant’s object returns not found.
Authentication
Local authentication is rate-limited. Sessions are recorded and revocable. SSO sessions are the same objects as password sessions and are revoked by the same code.
Audit
Governed actions write an audit record, and audit records cannot be given a deletion policy.
External assurance
Not asserted hereSome assurance can only be granted by an independent third party, and VoiceInsights does not assert any of it here. The Trust Center is the single governed place where every such item is published with its real status — outstanding items included, named individually, rather than omitted. Documentation deliberately does not restate those statuses: a second copy of an assurance claim is a copy that can drift, and the one that drifts is always the one somebody quotes.
What this does not do
Stated here rather than discovered later
- No SOC 2 report, no ISO/IEC 27001 certificate, no independent penetration test and no independently audited accessibility conformance is held. Each is named in the Procurement Center with the party who would have to produce it.
- No executed data processing agreement is recorded with any subprocessor.
- Jurisdiction controls exist in the underlying infrastructure and are not configured. No data-residency claim is made.