Trust

Security at Voxline

Answering the phone means handling sensitive data. Here’s how we protect it.

Encryption

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Third-party credentials you connect (calendars, telephony) are encrypted with per-tenant keys.

Tenant isolation

Every request is scoped to your organisation. Our API enforces tenant isolation on every route, so one customer can never reach another’s data.

Access control

  • Role-based access (owner, admin, member) within your organisation.
  • Least-privilege access for our staff, granted only when needed and logged.
  • Support for strong passwords today, with SSO on enterprise plans.

Prompt-injection defence

Business knowledge is treated as clearly-labelled reference data, never as instructions the agent must follow — and each agent can only use the tools you explicitly allow. This keeps a caller (or a crafted document) from steering the agent off task.

Reliability & backups

We run on managed infrastructure with automated backups and monitoring. Webhooks are processed idempotently so a retried event never double-books or double-charges.

Reporting an issue

Found a vulnerability? We’d like to hear from you. Email security@voxline.uk and we’ll respond promptly.