✦ Transparent Security & Compliance

Security built for mission-critical logistics.

Every technical claim on this page reflects our live AWS London production architecture and UK ICO baseline. No marketing exaggerations, no premature certifications.

Compliance & Governance Baseline

UK GDPR & Data Protection Act 2018 (Information Commissioner's Office Standard)
Phase 1 AWS Live • Phase 4 ICO Posture

VoxFlow operates as a high-integrity, solo-architected SaaS platform. Our data protection measures, subprocessor contracts, DSAR workflows, and retention purges are designed and enforced directly to UK Information Commissioner's Office (ICO) standards. Formal external certifications (such as SOC 2 Type II and ISO 27001) are part of our Phase 6 enterprise procurement milestone.

Pillar 01 — Physical & Cloud Infrastructure

AWS London (eu-west-2) Residency & Encryption

AWS RDS PostgreSQL 15.19

Dedicated relational database hosted exclusively in the AWS London (eu-west-2) region. Multi-AZ ready with strict security groups.

KMS Encryption at Rest

All database tables, transaction logs, automated snapshots, and EBS host volumes are encrypted at rest using AWS KMS with AES-256 keys.

Daily Backups & PITR

Automated daily database snapshots with 7-day Point-in-Time Recovery (PITR), verified via automated recovery drill scripts.

TLS 1.3 in Transit: Auto-renewed certificates via Caddy edge proxy with HSTS enabled
Inspect Live Health Check →
Pillar 02 — Telephony & AI Pipeline

Ephemeral Voice Inference & Audio Retention

Amazon Connect UK DID

Calls terminate on AWS Amazon Connect in London. Inbound routing matches strict tenant DIDs. Unknown numbers reject immediately with zero audio processing.

Zero-Retention AI Inference

Speech-to-text (Whisper) and LLM inference stream via Groq with enterprise zero-data-retention terms. Caller voice audio is never used to train machine learning models.

24h S3 Purge Lifecycle

Call audio stored in S3 London buckets is governed by an automated 24-hour expiration rule. Transcripts follow the workspace retention schedule (30 to 90 days).

Pillar 03 — Application Security & Access Control

Multi-Tenant Isolation & PBKDF2 Caller Hashing

Strict Tenant Scoping

Every query filters on authenticated tenant_id membership. Cross-tenant leakage is prevented at the database ledger level and validated by 580+ automated tests.

Salted PBKDF2 PINs

Driver and caller authentication PINs are hashed using PBKDF2 with 100,000 rounds and unique cryptographic salts. Plaintext PINs are never stored or logged.

Secrets in AWS Secrets Manager

Zero secrets or credentials exist in git history. Production environment variables are injected at deployment time via AWS KMS and secure host configuration.

Pillar 04 — Legal Posture & DSAR Rights

Automated Erasure, Export & Subprocessors

One-Click Right to Erasure & Export

Under UK GDPR Article 17, data subjects can request immediate erasure or machine-readable export of all call logs, transcripts, and metadata via automated backend API endpoints:

POST /api/privacy/erasure
GET /api/privacy/export

Subprocessor Transparency & DPA

We maintain a publicly published, audited subprocessor list. Any enterprise customer can execute a bilateral UK GDPR Data Processing Addendum (DPA) with standard contractual clauses.

Vulnerability Disclosure

Have a security finding to report?

We value the security research community. If you discover a potential vulnerability, please email our engineering team directly at security@voxflow.cc. We acknowledge reports within 24 hours.