Voxe Desk · Trust Center
Voxe Desk handles customer conversations, knowledge bases, and connected business data — so security is not optional. This page describes exactly where we stand today: what we do, what we can share, what we are building toward, and what we do not yet have.
Last reviewed: August 28, 2026
[email protected]Voxe Desk does not currently hold SOC 2, ISO 27001, HIPAA, or similar certifications, and nothing on this page should be read as claiming one. What we do have: real technical controls in the product, a maintained internal security and privacy program, published policies, and an active effort to formalize compliance as we grow. Every statement below is limited to what we can verify today.
The controls currently implemented in the product and our operations.
Everything is labeled by its real status: published, available on request, in progress, or not currently available.
What we collect, why, who we share it with, and your rights.
ViewCookies, browser storage, and similar technologies we use.
ViewThe agreement governing use of the Voxe Desk services.
ViewBilling, cancellation, and refund practices.
ViewThe service providers that support the platform, and why.
ViewThese documents exist and are maintained as part of our internal security and privacy program. We review every request manually and reply by email; some documents may require a mutual NDA.
Our internal security policy: objectives, roles, and core controls.
How accounts, credentials, and privileged access are managed.
Encryption standards for data in transit and at rest.
How long data is kept and how it is deleted.
How we detect, respond to, and communicate about incidents.
How we plan for outages and recovery.
The principles governing our use of AI systems.
We complete your standard vendor or security questionnaire.
A standardized DPA template is being finalized. Today, data-processing terms are agreed individually — request one and we will follow up.
We are mapping our controls to SOC 2 criteria as we build toward a future audit. We do not have a SOC 2 report and none is available yet.
We would rather tell you clearly what we do not have than imply otherwise. Registering interest genuinely shapes what we build next.
We are not ISO 27001 certified. Our internal policies follow its structure, but no certification exists.
No third-party penetration test report is available yet. Interest registered here helps us prioritize one.
We do not offer Business Associate Agreements, and the services are not intended for protected health information.
Tell us who you are and what you need. A person reviews every request and replies from [email protected], typically within a few business days.
Service providers that may process data in connection with the Services, depending on deployment and configuration. Each provider receives only the information reasonably necessary for its function — see our Privacy Policy for details.
| Provider | Purpose |
|---|---|
| OpenAI | AI model processing for AI-generated responses and embeddings |
| Fusion | AI workflow and model routing |
| n8n | Workflow automation |
| Jina AI | AI processing (embeddings and retrieval) |
| Chatwoot | Helpdesk and live-chat infrastructure |
| Stripe | Payment processing and billing |
| Authentication (OAuth) and calendar integration | |
| DigitalOcean Spaces | Object storage for uploaded files |
| Sentry | Error, security, and performance monitoring |
| Vercel Analytics | Website analytics, where enabled |
| CookieYes | Cookie consent management |
| ReferralRocket | Referral and affiliate attribution |
| Email provider (SMTP) | Transactional email delivery |
Not every provider is used on every page, plan, or deployment. Self-hosted deployments may use a different set of providers under your control.
Depending on the feature: prompts, conversation history, page context, system instructions, knowledge-base content, retrieved business data, and tool results. Data is sent only when reasonably necessary for the selected feature or workflow.
We do not train foundation models on your data, and we do not sell personal information. Provider-side retention and training practices vary by provider and configuration; we do not claim they are identical across providers.
You choose which integrations to connect and which AI features to enable, can configure page-context fields on your widget, and human handoff is always available. Self-hosting keeps data on your own infrastructure.
What we are actively working toward. None of these are certifications we hold today.
We are mapping our existing controls to SOC 2 criteria and closing gaps as we build toward a future audit. No report exists yet.
A standard Data Processing Addendum template customers can sign without negotiation. Until it ships, data-processing terms are agreed individually.
A third-party penetration test is on our roadmap. Interest registered through the request form directly influences when we prioritize it.
No. We do not currently hold SOC 2, ISO 27001, or similar certifications, and we will not imply otherwise. Our internal security policies follow the structure of these frameworks, and we are aligning our controls with SOC 2 criteria as we build toward a future audit. When a certification is achieved, it will be published here.
Data-processing terms are currently agreed individually with customers who need them. A standardized DPA template is being finalized — request one through the form above and we will follow up.
Managed deployments run on the infrastructure providers listed in the subprocessor table above. If you self-host Voxe, customer data stays on infrastructure you control.
Voxe does not train foundation models on customer data. AI features send data to the configured model providers only as needed to perform the selected function; each provider's data-use and retention practices are governed by that provider relationship, as described in our Privacy Policy.
Yes. Submit a request through the form above with your questionnaire or format, and we will complete it.
Email [email protected] with the details. Please do not include sensitive customer data in the report. We review and acknowledge every report.
Email [email protected] for security, privacy, or compliance questions, or use the request form above.
Voxe Desk is a registered assumed name of a Texas limited liability company. The information on this page describes our practices as of the date shown above and is provided for transparency; it does not modify the Terms of Service or any signed agreement.