Voxe Desk · Trust Center

Security and privacy, stated honestly

Voxe Desk handles customer conversations, knowledge bases, and connected business data — so security is not optional. This page describes exactly where we stand today: what we do, what we can share, what we are building toward, and what we do not yet have.

Last reviewed: August 28, 2026

[email protected]

Where we stand

Voxe Desk does not currently hold SOC 2, ISO 27001, HIPAA, or similar certifications, and nothing on this page should be read as claiming one. What we do have: real technical controls in the product, a maintained internal security and privacy program, published policies, and an active effort to formalize compliance as we grow. Every statement below is limited to what we can verify today.

Security overview

The controls currently implemented in the product and our operations.

Application & infrastructure

  • All traffic is encrypted in transit with HTTPS/TLS
  • Integration credentials and OAuth tokens are encrypted at rest (AES-256)
  • API rate limiting protects authentication and public endpoints
  • Error and reliability monitoring (Sentry) — session replay disabled

Account & access

  • Passwords are hashed with bcrypt and never stored in plaintext
  • Optional two-factor authentication (TOTP)
  • OAuth sign-in supported
  • Sessions are revoked on password reset
  • Role separation between user and administrative access

Data & privacy

  • Customer data is scoped to the owning account
  • Payments are processed by Stripe — full card numbers never touch our servers
  • We do not sell personal information
  • Data deletion on request, as described in our Privacy Policy
  • Cookie consent management on the production website

AI safety

  • Data is sent to AI providers only when needed for the selected feature
  • Voxe does not train foundation models on your data
  • Human handoff is built into every AI conversation flow
  • AI providers and models are configurable per workspace

Deployment options

  • Managed cloud deployment, or self-hosted on your own infrastructure
  • Self-hosted deployments keep customer data entirely within your environment

Operations

  • Security-relevant events are logged and monitored
  • Suspected account compromise handled via a dedicated support process
  • Vulnerability reports are reviewed and acknowledged — email us directly

Documents

Everything is labeled by its real status: published, available on request, in progress, or not currently available.

Published now

Available on request

These documents exist and are maintained as part of our internal security and privacy program. We review every request manually and reply by email; some documents may require a mutual NDA.

Available on request

Information Security Policy

Our internal security policy: objectives, roles, and core controls.

Available on request

Access Control Policy

How accounts, credentials, and privileged access are managed.

Available on request

Encryption Policy

Encryption standards for data in transit and at rest.

Available on request

Data Retention & Disposal Policy

How long data is kept and how it is deleted.

Available on request

Incident Response Procedure

How we detect, respond to, and communicate about incidents.

Available on request

Business Continuity Overview

How we plan for outages and recovery.

Available on request

AI Ethics & Transparency Policy

The principles governing our use of AI systems.

Available on request

Security questionnaire

We complete your standard vendor or security questionnaire.

In progress

In progress

Data Processing Addendum

A standardized DPA template is being finalized. Today, data-processing terms are agreed individually — request one and we will follow up.

In progress

SOC 2 alignment

We are mapping our controls to SOC 2 criteria as we build toward a future audit. We do not have a SOC 2 report and none is available yet.

Not currently available

We would rather tell you clearly what we do not have than imply otherwise. Registering interest genuinely shapes what we build next.

Not currently available

ISO 27001 certification

We are not ISO 27001 certified. Our internal policies follow its structure, but no certification exists.

Not currently available

Independent penetration test report

No third-party penetration test report is available yet. Interest registered here helps us prioritize one.

Not currently available

HIPAA BAA

We do not offer Business Associate Agreements, and the services are not intended for protected health information.

Request access

Tell us who you are and what you need. A person reviews every request and replies from [email protected], typically within a few business days.

Documents

We use this information only to respond to your request and to understand which documentation our customers need, as described in our Privacy Policy. Submitting does not create any account or subscription.

Subprocessors

Service providers that may process data in connection with the Services, depending on deployment and configuration. Each provider receives only the information reasonably necessary for its function — see our Privacy Policy for details.

ProviderPurpose
OpenAIAI model processing for AI-generated responses and embeddings
FusionAI workflow and model routing
n8nWorkflow automation
Jina AIAI processing (embeddings and retrieval)
ChatwootHelpdesk and live-chat infrastructure
StripePayment processing and billing
GoogleAuthentication (OAuth) and calendar integration
DigitalOcean SpacesObject storage for uploaded files
SentryError, security, and performance monitoring
Vercel AnalyticsWebsite analytics, where enabled
CookieYesCookie consent management
ReferralRocketReferral and affiliate attribution
Email provider (SMTP)Transactional email delivery

Not every provider is used on every page, plan, or deployment. Self-hosted deployments may use a different set of providers under your control.

AI & data handling

What gets sent to AI providers

Depending on the feature: prompts, conversation history, page context, system instructions, knowledge-base content, retrieved business data, and tool results. Data is sent only when reasonably necessary for the selected feature or workflow.

What we do not do

We do not train foundation models on your data, and we do not sell personal information. Provider-side retention and training practices vary by provider and configuration; we do not claim they are identical across providers.

Your controls

You choose which integrations to connect and which AI features to enable, can configure page-context fields on your widget, and human handoff is always available. Self-hosting keeps data on your own infrastructure.

Compliance roadmap

What we are actively working toward. None of these are certifications we hold today.

SOC 2 alignment

We are mapping our existing controls to SOC 2 criteria and closing gaps as we build toward a future audit. No report exists yet.

In progress

Standardized DPA

A standard Data Processing Addendum template customers can sign without negotiation. Until it ships, data-processing terms are agreed individually.

In progress

Independent security testing

A third-party penetration test is on our roadmap. Interest registered through the request form directly influences when we prioritize it.

Planned

Frequently asked questions

Are you SOC 2 or ISO 27001 certified?

No. We do not currently hold SOC 2, ISO 27001, or similar certifications, and we will not imply otherwise. Our internal security policies follow the structure of these frameworks, and we are aligning our controls with SOC 2 criteria as we build toward a future audit. When a certification is achieved, it will be published here.

Will you sign a Data Processing Addendum (DPA)?

Data-processing terms are currently agreed individually with customers who need them. A standardized DPA template is being finalized — request one through the form above and we will follow up.

Where is my data hosted?

Managed deployments run on the infrastructure providers listed in the subprocessor table above. If you self-host Voxe, customer data stays on infrastructure you control.

Is my data used to train AI models?

Voxe does not train foundation models on customer data. AI features send data to the configured model providers only as needed to perform the selected function; each provider's data-use and retention practices are governed by that provider relationship, as described in our Privacy Policy.

Can you complete our security questionnaire?

Yes. Submit a request through the form above with your questionnaire or format, and we will complete it.

How do I report a security vulnerability?

Email [email protected] with the details. Please do not include sensitive customer data in the report. We review and acknowledge every report.

Questions we did not answer?

Email [email protected] for security, privacy, or compliance questions, or use the request form above.

Voxe Desk is a registered assumed name of a Texas limited liability company. The information on this page describes our practices as of the date shown above and is provided for transparency; it does not modify the Terms of Service or any signed agreement.