# Security and trust

Last updated: 2026-10-05

Vocenya answers calls, texts and chats for your business, so it handles information your customers trust you with. This page explains, in plain language, how we protect it. Questions? Email [info@gh-businesssolutions.com](mailto:info@gh-businesssolutions.com).

## Where your data lives
- Vocenya runs on **Amazon Web Services (AWS) in the United States**, in the us-east-1 region (Northern Virginia): the web platform, the database, the cache and queues, call recordings, and the voice engine that answers calls.
- The AI models we use for calls, summaries and chats run on **Amazon Bedrock** in the same AWS account. Anthropic's own API is used as a backup when Bedrock is unavailable.
- Call audio travels over the phone network through our carrier, Telnyx.
- Every company that processes customer data for us is listed on our [sub-processors page](/subprocessors), with what it receives and where.

## Encryption
- **In transit:** our website, portal, apps and APIs are served over HTTPS (TLS). Connections from our servers to the database and to the cache require TLS.
- **Call recordings** are stored in Amazon S3 encrypted with keys managed in AWS Key Management Service (KMS). Other stored audio, such as call briefings and voice previews, is encrypted in S3 with AES-256.
- **Playback links** to a recording are signed and expire after a few minutes.
- **Secrets we hold for you**, such as connected-app tokens, API credentials, webhook secrets and number-porting PINs, are encrypted in our database. Sessions are encrypted.
- **Passwords and API keys** are stored only as one-way hashes. Card numbers never touch our servers: Stripe holds them.

## HIPAA mode for healthcare
Healthcare practices can turn on HIPAA mode once our business associate agreement (BAA) is published. In HIPAA mode:
- Calls always use our **Standard voice engine, which runs entirely on AWS**. Third-party voice providers (ElevenLabs, Deepgram, Cartesia) are never used.
- **WhatsApp, the Shopify app and Notion can't be connected**, and other integrations only receive caller details after you confirm you have a BAA with that vendor.
- **Emails, push notifications and texts leave out patient details.** You see them when you sign in. Texts are limited to short notices, and the AI doesn't hold text conversations.
- Recordings are kept in our own encrypted storage, not by the carrier.
- Our optional text-classification provider is never used for HIPAA-mode accounts, or for any healthcare business.

See the [HIPAA AI receptionist page](/hipaa-ai-receptionist) for more.

## Who can access your account
- **Two-factor authentication** (an authenticator app, with recovery codes) and **passkeys** are available to every user under Settings.
- **Roles:** account owners control billing, the team and deletion; staff members get day-to-day access without those controls.
- **Vocenya staff access is limited and audited.** When our support team needs to see your account, they open a read-only "view as" session that requires a written reason, lasts at most 30 minutes, and logs the pages viewed, recordings played and questions asked. For HIPAA-mode accounts, staff must also acknowledge that the account holds health information before starting.
- **Audit log:** recording playback and deletion, transcript deletion, billing changes and staff sessions are recorded in an audit log.
- **Deletion:** owners can delete a call's recording and transcript or a chat's messages, or have recordings and transcripts deleted automatically after 30, 90 or 365 days.

## Live agents
If you use GH Live, calls and chats handed to a person are answered by trained agents of our affiliate GH Business Solutions, some of whom work from the Philippines. They see only the conversation handed to them and are bound by confidentiality obligations.

## System status
Live status for the platform, calls, messaging and billing is at [status.vocenya.com](https://status.vocenya.com). It runs on separate infrastructure, so it stays up if Vocenya is down, and you can subscribe to incident emails there.

## Report a vulnerability
If you think you've found a security issue in Vocenya, email [info@gh-businesssolutions.com](mailto:info@gh-businesssolutions.com) with "Security" in the subject, the steps to reproduce it and its impact. Please give us a reasonable time to fix it before telling anyone else, and don't access other customers' data, disrupt the service or run automated scans that degrade it. We will acknowledge your report, keep you updated and won't take legal action against good-faith research that follows these guidelines.

## Related
- [Privacy Policy](/privacy)
- [Data Processing Addendum](/dpa)
- [Sub-processors](/subprocessors)
- [Acceptable Use Policy](/acceptable-use)
- [Cookie Notice](/cookies)

---

Source: https://vocenya.com/security
Vocenya, powered by GH Business Solutions. Plans from $49/month with a 14-day free trial: https://vocenya.com/pricing
