Security

Your controls, your environment, your logs.

Because the system runs on your infrastructure, it sits inside the security controls you already operate and certify. Here is what we add on top.

Runs in
Your environment
Access
Role-based, directory-synced
Training on your data
Never, except your own models
Certifications
Not yet held; yours apply

In short

DeepVox systems run inside the client’s own infrastructure, so they inherit the client’s network, identity, monitoring and certification controls. On top, DeepVox builds role-based access by department and person, separates asking from acting, logs every query and action, never sends client data to us or a model provider unless the client chooses, and hands over code and runbooks.

Controls

What we build in.

Deployment in your environment

Connectors, index, models, voice and logs on your servers or private cloud.

Role-based access

By department, role and person, synced from Entra ID, Keycloak or your directory.

Ask vs act

Reading and changing records are separate permissions, with approval gates.

Audit trail

Every query, source, answer, approval and action logged where you keep it.

Model gateway controls

Hosted models can be blocked per agent; usage and cost visible per department.

No training on your data

Nothing goes to us or a model provider; fine-tuned models are trained in your environment and belong to you.

Engineering practice

How we work on your systems.

  • Open-source components you can inspect, with licence risks tracked and disclosed.
  • Access to your environment agreed in advance and limited to what the work needs.
  • Runbooks and documentation as contracted deliverables.
  • Managed support with a 99.9% uptime SLA, if you choose it.
  • A rehearsed exit test so your team or a successor can take over.

Certifications

Honest status.

DeepVox does not yet hold ISO 27001, SOC 2 or similar certifications, and we won’t show badges until we do. Because your deployment runs inside your environment, it falls under the certified controls you already operate.

For security questions, or to report a vulnerability, write to sales@deepvox.ai with “Security” in the subject.

FAQ

Questions, answered.

Do you need access to our production data?

Only what the agreed work needs, under your access controls, and only if you approve it.

Can your team see our users’ questions?

Not unless you give us access, for example under managed support. Logs stay in your environment.