Security

Voice is one of the most sensitive data types your customers will ever generate. Here's how we treat it.

Last updated: May 7, 2026

🔐

Encryption everywhere

TLS 1.2+ for everything in transit, including the voice WebSocket leg. Audio recordings and transcripts encrypted at rest with AES-256. Separate keys per customer on Advanced and Enterprise plans.

🪪

Authentication & access

Per-customer role-based access control (Admin, Owner, User). Optional Google and Facebook OAuth. Brute-force protection on login (account lockout after repeated failures). Optional reCAPTCHA on auth forms. SSO/SAML available on Enterprise.

🧱

Customer isolation

Strict tenant_id enforcement at the database, API, and storage layers. Cross-tenant access is blocked by default and gated behind a feature flag we can't disable per request.

📜

Audit trail

Every API call records who did what and when. Account admins can export a full audit log; on Enterprise plans we ship logs into your SIEM (Splunk, Datadog, Elastic).

🔄

Backups & recovery

Encrypted nightly backups of your configuration and metadata, retained for 30 days. RTO ≤ 4h and RPO ≤ 24h, with a documented disaster-recovery runbook.

Compliance

GDPR

Designed for compliance from day one. EU region available, DPA on request.

UK GDPR

Same posture; UK region available.

SOC 2

Type I in progress; Type II target H2 2026.

HIPAA

BAA available on Enterprise.

PCI

We never see card data — payment processing is offloaded to a certified processor.

Reporting a vulnerability

We want to hear about it. Email hello@siluxvoice.com with details (proof-of-concept, affected endpoint, impact). We acknowledge within 48 hours and aim to remediate or mitigate within 14 days for high-severity issues.

Please don't run automated scanners against production — ask us for a sandbox and we'll set one up for you.