Compliance the buyer actually reads.
Every certification, sub-processor, retention policy, and encryption choice we make, written for the person who has to sign off on your security review rather than the person whose job it is to sell you anything.
Eight frameworks, one conversation.
AI-specific compliance (ISO 42001, EU AI Act) sits in the same row as classic infrastructure compliance (SOC 2, ISO 27001), because they should.
- SOC 2 Type IIProgram underway: controls implemented and evidence collection live ahead of the independent audit window. Evidence package available under NDA via your account team.In progress
- ISO 27001Information security management system certification. Controls aligned today.On the roadmap
- ISO 42001AI management system standard, the AI-specific extension of 27001.On the roadmap
- HIPAA readinessPHI stays in your system of record by design. Business Associate Agreement offered on healthcare master agreements.BAA offered for healthcare deployments
- GDPR · UK GDPREU and UK data subject rights honored. DPA with standard SCCs available.DPA available
- EU AI ActObligations for applicable deployments tracked; transparency documentation available on request.Tracked
- PCI DSS 4.0No card data ever touches Vorel infrastructure. Payment surfaces redirect to PCI-scoped vaults.Not in scope by design
- TCPA + per-stateOutbound voice and SMS enforce TCPA consent and per-state quiet-hours by default.Enforced at runtime
Every byte, every boundary.
Your data stays where you said it would.
Pick a region at contract time. Customer data does not leave it. Vorel never cross-replicates customer payloads between regions. Operational telemetry is the only thing that does, and that telemetry contains no PII.
United States
Primary hosting region on managed cloud infrastructure. Default for all customers today.
European Union · United Kingdom
DPA with standard SCCs covers EU and UK data subjects today. In-region hosting is on the roadmap.
GCC + Middle East
Regional deployment available on enterprise agreements. Talk to us about sovereignty requirements.
Other regions
Tell us what your regulator requires and we will scope it with you before you sign.
We don't keep what we don't need.
The supply chain, by category.
The categories of third party Vorel relies on and where they sit. The named sub-processor list is provided with the DPA to customers and prospects under NDA, and we notify customers at least thirty days before a new sub-processor is added.
| Category | Purpose | Region |
|---|---|---|
| Cloud infrastructure | Compute, storage, networking | US |
| Telephony carrier | Voice and SMS interconnect | Global |
| Speech vendors | Speech-to-text and speech synthesis | US / EU |
| Foundation model providers | Multi-vendor LLM layer under no-training API terms | US |
| Billing | Usage metering and invoicing | Global |
| Identity | Operator console authentication | US |
| Email delivery | Transactional email | US |
Found something? Tell us first.
Responsible disclosure goes to [email protected]. PGP public key on request. We acknowledge within twenty-four hours, fix within the contract SLA, and credit the reporter unless they prefer otherwise.
What security teams ask
How do I report a security issue?
Where are the legal documents?
How are sub-processor changes communicated?
Do you train models on our customer data?
Bring your security questionnaire.
We'll bring the audit trail. Thirty minutes with the team that wrote this page.

