Trust & compliance

Security and compliance aren't a layer we add later — they're at the center of the design. We deliver the data security and regulatory compliance that banks, collections and the public sector require, as standard.

Data Sovereignty & Location

Our data center is in the EU; all our models run on our own servers.

Data is never sent to third-party or foreign AI services.

Servers are fully closed to external access, except the API services.

On-premise deployment for high-sensitivity organizations; otherwise a cloud closed to external access.

Encryption & Network Security

OV SSL/TLS encryption in transit.

Isolated, private network; servers closed to external access.

API access is filtered to the customer's IP via firewall.

Backups are stored encrypted on servers closed to external access.

Access Control

Role-based access (permission levels).

Two-factor authentication (2FA) for panel users.

Header-based authentication and IP filtering for API services.

Data Lifecycle & Retention

In API usage, the audio file is deleted immediately after processing.

In the API, the analysis result is kept for 1 month by default; you can set this period.

In the panel, data is retained according to your preference so you can access it.

Compliance & Roles

KVKK and GDPR compliant.

The customer is the data controller; Vocal Future is the data processor.

We have a data-breach notification process (within 72 hours at the latest).

Service Continuity

99.5% service availability (uptime) target.

Certifications

Information security and quality management certified by an independent accredited body.

ISO/IEC 27001:2022
Kiwa · Cert. No: M 12264 · Valid until: 11.05.2028
View certificate (PDF)
ISO 9001:2015
Kiwa · Cert. No: M 12263 · Valid until: 11.05.2028
View certificate (PDF)

Request security documentation or a demo

Let's review your enterprise security and compliance requirements together.