Skip to content
Vaakyo

Security

Your customers' conversations, protected

Calls carry names, numbers and sometimes payment details. Here is how we keep them safe.

  • TLS everywhere
  • Encrypted storage
  • Two-step sign-in
  • Role-based access
  • Audit log
  • Signed webhooks

Encryption

  • Every connection to the console, the API and our speech and telephony providers uses TLS.
  • Recordings, uploads and backups are stored in encrypted cloud storage.
  • Provider keys and two-step verification secrets are encrypted before they are stored; recovery codes and API keys are stored hashed.

Access control

  • Each workspace's data is separate: every request is checked against the workspace it belongs to.
  • Roles (owner, admin, developer and viewer) decide who can see calls, edit agents or manage billing.
  • Two-step verification with an authenticator app, and sign-in sessions you can end from the console.

API and integrations

  • API keys carry only the permissions you give them, and can be revoked at any time.
  • Webhooks are signed (HMAC-SHA256 with a timestamp), so your server can check they came from us.
  • AI apps connect over the MCP server with OAuth 2.1 and PKCE, with permissions capped and re-checked on every request.
  • Tools an agent calls must be on the public internet: private and internal addresses are refused.

Accountability

  • Every change by a person or a key (agents, numbers, members, billing) is written to an audit log your admins can read.
  • Every workspace is verified (KYC) before it can call customers.
  • Our own team signs in with two-step verification, and support access is read-only.

Responsible calling

  • Queued outbound calls wait for the agent's calling hours, and each campaign has its own calling window.
  • Every call is checked afterwards against platform rules, including TRAI's 9:00 to 21:00 IST window for promotional calls. Repeated violations freeze the agent until our team has reviewed it.
  • Agents can be told to identify themselves as AI and to end the call when asked.
  • Our Acceptable Use Policy forbids spam, calls to DND numbers without consent and impersonation.

Where your data is

  • Call recordings, uploaded files and the nightly database backups are kept in Azure Blob Storage, encrypted at rest.
  • Transcripts and call data are kept in Vaakyo's database, separated by workspace.
  • During a call, the audio and text go to the speech and language models you chose for that agent, and nowhere else.
  • Recording can be switched off for any agent.

Indian data protection law

  • Our privacy policy is written to meet the Digital Personal Data Protection Act, 2023 and the IT Act, 2000.
  • For the people your agents speak with, you are the data fiduciary and Vaakyo is your data processor: we use their data only to run your calls.
  • Some speech and language providers process data outside India. We transfer data only to countries the Government of India has not restricted under the DPDP Act.
  • A named grievance officer answers privacy complaints, as the Act requires.

Reliability

  • Nightly encrypted backups of the database, kept for a rolling window.
  • Zero-downtime deploys: live calls finish on the old version while new calls start on the new one.
  • Speech providers have automatic fallbacks, so one vendor's outage doesn't drop your calls.

Found a security issue?

Please email hello@vaakyo.comwith the details and steps to reproduce. We'll reply quickly and won't take action against good-faith research.