Trust Center

Compliance the buyer actually reads.

Every certification, sub-processor, retention policy, and encryption choice we make, written for the person who has to sign off on your security review rather than the person whose job it is to sell you anything.

[email protected]Responsible disclosure at [email protected] (PGP on request)
Controls

Eight frameworks, one conversation.

AI-specific compliance (ISO 42001, EU AI Act) sits in the same row as classic infrastructure compliance (SOC 2, ISO 27001), because they should.

  • SOC 2 Type IIIndependently audited. Report available under NDA via your account team.Audited
  • ISO 27001Information security management system certification.In progress, Q4 2026
  • ISO 42001AI management system standard, the AI-specific extension of 27001.In progress, Q1 2027
  • HIPAA + BAABusiness Associate Agreement signed on every healthcare master agreement. The BAA is non-optional, not a customization.Signed by default for healthcare deployments
  • GDPR · UK GDPREU and UK data subject rights honored. DPA available under standard terms.Compliant
  • EU AI ActHigh-risk AI system controls aligned with AGS-2 conformance criteria.Aligned
  • PCI DSS 4.0No card data ever touches Vorel infrastructure. Payment surfaces redirect to PCI-scoped vaults.Not in scope by design
  • TCPA + per-stateOutbound voice and SMS enforce TCPA consent and per-state quiet-hours by default.Enforced at runtime
Encryption

Every byte, every boundary.

In transit
TLS 1.3 across every Vorel surface, certificate-pinned for first-party traffic. Mutual TLS for service-to-service calls inside the cluster.
At rest
AES-256 envelope encryption against KMS-managed keys. Per-tenant data isolation; keys rotate quarterly and are revocable on contract termination.
In the model
PII is redacted from the conversation payload sent to model providers, except in the narrow cases the customer's flow requires it. Redacted tokens never appear in training data, full stop.
Data residency

Your data stays where you said it would.

Pick a region at contract time. Customer data does not leave it. Vorel never cross-replicates customer payloads between regions. Operational telemetry is the only thing that does, and that telemetry contains no PII.

  • North America

    US-East and US-West regions on AWS. Default for US-headquartered customers.

  • European Union

    eu-west-1 (Ireland) and eu-central-1 (Frankfurt). Data does not leave the region.

  • United Kingdom

    eu-west-2 (London). UK-GDPR aligned.

  • GCC + Middle East

    me-central-1 (UAE). Sovereign-data deployment available.

  • India

    ap-south-1 (Mumbai).

  • Latam + APAC

    Expansions in flight. Talk to us if you need a specific region today.

Retention

We don't keep what we don't need.

Audio
30 days default. Configurable down to 0 days. Customer-controlled in your tenant settings.
Transcripts
Customer-controlled. The transcript lives in your CRM, not ours. We retain operational telemetry only.
Operational telemetry
90 days. Used for incident response and SLA reporting. No customer PII.
Training data
We do not train on your customer data without an explicit, written opt-in. The default is no.
Sub-processors

The full supply chain.

Every third party Vorel relies on, what they do for us, and where they sit. We notify customers at least thirty days before a new sub-processor is added.

Sub-processorPurposeRegion
AWSCompute, storage, networkingPer residency selection
Twilio / VonageVoice and SMS carrier interconnectPer residency
Anthropic, OpenAI, GoogleFoundation model providers (multi-vendor, redacted payloads)Per residency
DatadogObservability (no PII)US / EU
StripeBilling meter and invoicingGlobal
ClerkOperator console authenticationUS
Disclosure

Found something? Tell us first.

Responsible disclosure goes to [email protected]. PGP public key on request. We acknowledge within twenty-four hours, fix within the contract SLA, and credit the reporter unless they prefer otherwise.

FAQ

What security teams ask

How do I report a security issue?
Responsible disclosure goes to [email protected]. PGP public key on request. We acknowledge within twenty-four hours, fix within the contract SLA, and credit the reporter unless they prefer otherwise. Machine-readable details live at security.txt.
Where are the legal documents?
The privacy policy, terms of service, and data processing agreement are published here. Contract questions go to [email protected].
How are sub-processor changes communicated?
We notify customers at least thirty days before a new sub-processor is added. The full list above covers every third party Vorel relies on, what they do for us, and where they sit.
Do you train models on our customer data?
No. We do not train on your customer data without an explicit, written opt-in. The default is no, and redacted tokens never appear in training data.

Bring your security questionnaire.

We'll bring the audit trail. Thirty minutes with the team that wrote this page.