Security built for
mission-critical logistics.
Every technical claim on this page reflects our live AWS London production architecture and UK ICO baseline. No marketing exaggerations, no premature certifications.
Compliance & Governance Baseline
UK GDPR & Data Protection Act 2018 (Information Commissioner's Office Standard)VoxFlow operates as a high-integrity, solo-architected SaaS platform. Our data protection measures, subprocessor contracts, DSAR workflows, and retention purges are designed and enforced directly to UK Information Commissioner's Office (ICO) standards. Formal external certifications (such as SOC 2 Type II and ISO 27001) are part of our Phase 6 enterprise procurement milestone.
AWS London (eu-west-2) Residency & Encryption
Dedicated relational database hosted exclusively in the AWS London (eu-west-2) region. Multi-AZ ready with strict security groups.
All database tables, transaction logs, automated snapshots, and EBS host volumes are encrypted at rest using AWS KMS with AES-256 keys.
Automated daily database snapshots with 7-day Point-in-Time Recovery (PITR), verified via automated recovery drill scripts.
Ephemeral Voice Inference & Audio Retention
Calls terminate on AWS Amazon Connect in London. Inbound routing matches strict tenant DIDs. Unknown numbers reject immediately with zero audio processing.
Speech-to-text (Whisper) and LLM inference stream via Groq with enterprise zero-data-retention terms. Caller voice audio is never used to train machine learning models.
Call audio stored in S3 London buckets is governed by an automated 24-hour expiration rule. Transcripts follow the workspace retention schedule (30 to 90 days).
Multi-Tenant Isolation & PBKDF2 Caller Hashing
Every query filters on authenticated tenant_id membership. Cross-tenant leakage is prevented at the database ledger level and validated by 580+ automated tests.
Driver and caller authentication PINs are hashed using PBKDF2 with 100,000 rounds and unique cryptographic salts. Plaintext PINs are never stored or logged.
Zero secrets or credentials exist in git history. Production environment variables are injected at deployment time via AWS KMS and secure host configuration.
Automated Erasure, Export & Subprocessors
One-Click Right to Erasure & Export
Under UK GDPR Article 17, data subjects can request immediate erasure or machine-readable export of all call logs, transcripts, and metadata via automated backend API endpoints:
Subprocessor Transparency & DPA
We maintain a publicly published, audited subprocessor list. Any enterprise customer can execute a bilateral UK GDPR Data Processing Addendum (DPA) with standard contractual clauses.
Have a security finding to report?
We value the security research community. If you discover a potential vulnerability, please email our engineering team directly at security@voxflow.cc. We acknowledge reports within 24 hours.