Trust Center

Compliance the buyer actually reads.

Every certification, sub-processor, retention policy, and encryption choice we make, written for the person who has to sign off on your security review rather than the person whose job it is to sell you anything.

[email protected]Responsible disclosure at [email protected] (PGP on request)
Controls

Eight frameworks, one conversation.

AI-specific compliance (ISO 42001, EU AI Act) sits in the same row as classic infrastructure compliance (SOC 2, ISO 27001), because they should.

  • SOC 2 Type IIProgram underway: controls implemented and evidence collection live ahead of the independent audit window. Evidence package available under NDA via your account team.In progress
  • ISO 27001Information security management system certification. Controls aligned today.On the roadmap
  • ISO 42001AI management system standard, the AI-specific extension of 27001.On the roadmap
  • HIPAA readinessPHI stays in your system of record by design. Business Associate Agreement offered on healthcare master agreements.BAA offered for healthcare deployments
  • GDPR · UK GDPREU and UK data subject rights honored. DPA with standard SCCs available.DPA available
  • EU AI ActObligations for applicable deployments tracked; transparency documentation available on request.Tracked
  • PCI DSS 4.0No card data ever touches Vorel infrastructure. Payment surfaces redirect to PCI-scoped vaults.Not in scope by design
  • TCPA + per-stateOutbound voice and SMS enforce TCPA consent and per-state quiet-hours by default.Enforced at runtime
Encryption

Every byte, every boundary.

In transit
TLS 1.2+ on every public Vorel surface.
At rest
Data encrypted at rest on managed cloud infrastructure. Per-tenant isolation enforced with database row-level security on every tenant table, and the conversation log is append-only at the database layer.
In the model
Model providers are used under no-training API terms: your customer data is not used to train shared models. Operational telemetry is PII-redacted by default.
Data residency

Your data stays where you said it would.

Pick a region at contract time. Customer data does not leave it. Vorel never cross-replicates customer payloads between regions. Operational telemetry is the only thing that does, and that telemetry contains no PII.

  • United States

    Primary hosting region on managed cloud infrastructure. Default for all customers today.

  • European Union · United Kingdom

    DPA with standard SCCs covers EU and UK data subjects today. In-region hosting is on the roadmap.

  • GCC + Middle East

    Regional deployment available on enterprise agreements. Talk to us about sovereignty requirements.

  • Other regions

    Tell us what your regulator requires and we will scope it with you before you sign.

Retention

We don't keep what we don't need.

Audio
Call audio follows your telephony configuration; Vorel does not retain audio beyond operational processing by default.
Transcripts
Conversation logs are tenant-isolated and append-only at the database layer. Summaries, outcomes, and audit rows are mirrored into your CRM as the working record.
Operational telemetry
Used for incident response and quality reporting. PII-redacted by default.
Training data
We do not train on your customer data without an explicit, written opt-in. The default is no.
Sub-processors

The supply chain, by category.

The categories of third party Vorel relies on and where they sit. The named sub-processor list is provided with the DPA to customers and prospects under NDA, and we notify customers at least thirty days before a new sub-processor is added.

CategoryPurposeRegion
Cloud infrastructureCompute, storage, networkingUS
Telephony carrierVoice and SMS interconnectGlobal
Speech vendorsSpeech-to-text and speech synthesisUS / EU
Foundation model providersMulti-vendor LLM layer under no-training API termsUS
BillingUsage metering and invoicingGlobal
IdentityOperator console authenticationUS
Email deliveryTransactional emailUS
Disclosure

Found something? Tell us first.

Responsible disclosure goes to [email protected]. PGP public key on request. We acknowledge within twenty-four hours, fix within the contract SLA, and credit the reporter unless they prefer otherwise.

FAQ

What security teams ask

How do I report a security issue?
Responsible disclosure goes to [email protected]. PGP public key on request. We acknowledge within twenty-four hours, fix within the contract SLA, and credit the reporter unless they prefer otherwise. Machine-readable details live at security.txt.
Where are the legal documents?
The privacy policy, terms of service, and data processing agreement are published here. Contract questions go to [email protected].
How are sub-processor changes communicated?
We notify customers at least thirty days before a new sub-processor is added. The named list is provided with the DPA under NDA; the categories above cover what each third party does for us and where it sits.
Do you train models on our customer data?
No. We do not train on your customer data without an explicit, written opt-in. The default is no, and redacted tokens never appear in training data.

Bring your security questionnaire.

We'll bring the audit trail. Thirty minutes with the team that wrote this page.