Trust
Security at Voxline
Answering the phone means handling sensitive data. Here’s how we protect it.
Encryption
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Third-party credentials you connect (calendars, telephony) are encrypted with per-tenant keys.
Tenant isolation
Every request is scoped to your organisation. Our API enforces tenant isolation on every route, so one customer can never reach another’s data.
Access control
- Role-based access (owner, admin, member) within your organisation.
- Least-privilege access for our staff, granted only when needed and logged.
- Support for strong passwords today, with SSO on enterprise plans.
Prompt-injection defence
Business knowledge is treated as clearly-labelled reference data, never as instructions the agent must follow — and each agent can only use the tools you explicitly allow. This keeps a caller (or a crafted document) from steering the agent off task.
Reliability & backups
We run on managed infrastructure with automated backups and monitoring. Webhooks are processed idempotently so a retried event never double-books or double-charges.
Reporting an issue
Found a vulnerability? We’d like to hear from you. Email security@voxline.uk and we’ll respond promptly.