Security
Your customers' conversations, protected
Calls carry names, numbers and sometimes payment details. Here is how we keep them safe.
- TLS everywhere
- Encrypted storage
- Two-step sign-in
- Role-based access
- Audit log
- Signed webhooks
Encryption
- Every connection to the console, the API and our speech and telephony providers uses TLS.
- Recordings, uploads and backups are stored in encrypted cloud storage.
- Provider keys and two-step verification secrets are encrypted before they are stored; recovery codes and API keys are stored hashed.
Access control
- Each workspace's data is separate: every request is checked against the workspace it belongs to.
- Roles (owner, admin, developer and viewer) decide who can see calls, edit agents or manage billing.
- Two-step verification with an authenticator app, and sign-in sessions you can end from the console.
API and integrations
- API keys carry only the permissions you give them, and can be revoked at any time.
- Webhooks are signed (HMAC-SHA256 with a timestamp), so your server can check they came from us.
- AI apps connect over the MCP server with OAuth 2.1 and PKCE, with permissions capped and re-checked on every request.
- Tools an agent calls must be on the public internet: private and internal addresses are refused.
Accountability
- Every change by a person or a key (agents, numbers, members, billing) is written to an audit log your admins can read.
- Every workspace is verified (KYC) before it can call customers.
- Our own team signs in with two-step verification, and support access is read-only.
Responsible calling
- Queued outbound calls wait for the agent's calling hours, and each campaign has its own calling window.
- Every call is checked afterwards against platform rules, including TRAI's 9:00 to 21:00 IST window for promotional calls. Repeated violations freeze the agent until our team has reviewed it.
- Agents can be told to identify themselves as AI and to end the call when asked.
- Our Acceptable Use Policy forbids spam, calls to DND numbers without consent and impersonation.
Where your data is
- Call recordings, uploaded files and the nightly database backups are kept in Azure Blob Storage, encrypted at rest.
- Transcripts and call data are kept in Vaakyo's database, separated by workspace.
- During a call, the audio and text go to the speech and language models you chose for that agent, and nowhere else.
- Recording can be switched off for any agent.
Indian data protection law
- Our privacy policy is written to meet the Digital Personal Data Protection Act, 2023 and the IT Act, 2000.
- For the people your agents speak with, you are the data fiduciary and Vaakyo is your data processor: we use their data only to run your calls.
- Some speech and language providers process data outside India. We transfer data only to countries the Government of India has not restricted under the DPDP Act.
- A named grievance officer answers privacy complaints, as the Act requires.
Reliability
- Nightly encrypted backups of the database, kept for a rolling window.
- Zero-downtime deploys: live calls finish on the old version while new calls start on the new one.
- Speech providers have automatic fallbacks, so one vendor's outage doesn't drop your calls.
Found a security issue?
Please email hello@vaakyo.comwith the details and steps to reproduce. We'll reply quickly and won't take action against good-faith research.