Security & compliance.

The trust posture a small practice needs to put their patient calls through Voipy. We cover this page with the same factual-first / sourced approach as our competitor comparisons — what we do, what we don't, and what's on the roadmap.

Last updated: April 25, 2026

Compliance posture at a glance

In production HIPAA BAA available TLS 1.2+ in transit AES-256 at rest Per-tenant isolation Two-factor admin auth Vulnerability disclosure

In progress SOC 2 Type II preparation PCI SAQ-A scope confirmation Penetration test scheduled Q3 2026

Not yet SOC 2 Type II report ISO 27001 HITRUST

If a buyer's procurement requires a framework on the "Not yet" list, contact security@voipy.app — we'll confirm timeline and whether your renewal cycle aligns with our roadmap.

HIPAA

Voipy executes a Business Associate Agreement with healthcare customers on Pro and Enterprise plans. Our standard BAA covers the customer-facing call data lifecycle (intake, transcript, recording, retention, deletion). For customers who require their own paper, we sign reasonable counter-templates within ~5 business days of receipt.

What's BAA-covered

What sits outside the BAA

Request a BAA: support@voipy.app — include your tenant slug and signing party.

Encryption

In transit

All HTTP traffic to voipy.app and our internal API surfaces use TLS 1.2 or higher. Telephony media (RTP) is protected via SRTP between Voipy and Telnyx; SIP signaling uses TLS. Internal service-to-service calls inside our private VPC use mTLS where available.

At rest

PostgreSQL primary storage is encrypted with AES-256 at the volume layer. Recording audio files are encrypted at rest with per-tenant key derivation; retention policy applies before any backup snapshotting.

Authentication & access

Sub-processors

Sub-processors that handle customer or patient data on our behalf:

Sub-processorServiceData categoryRegion
TelnyxTelephony (SIP, SMS, recording)Call audio, SMS bodies, caller numbersUS
StripePayment processingCustomer billing only — no PHIUS
AnthropicLLM inference (production failover)Call transcript snippets, no patient identifiersUS
Google Cloud (Gemini)LLM inference (production failover)Call transcript snippets, no patient identifiersUS
Google Cloud (Speech-to-Text)Backup transcription pathCall audio (transient), no retentionUS
Self-hosted GPU (CT3)Primary STT / LLM / TTS pipelineCall audio, real-time onlyUS (private infrastructure)
CloudflareCDN + DDoS protectionPublic-marketing only — no PHI surfaceGlobal
Sentry (subscription pending)Error trackingDe-identified stack traces, no PHIUS

Sub-processor changes ship via a 30-day notice period to all paid customers. Material changes (new region, new data category) require BAA-customer re-execution if HIPAA scope changes.

Data retention & deletion

Incident response

If we discover a security incident affecting customer or patient data, we follow a documented response plan:

  1. Contain — disable the affected pathway within 1 hour of confirmation.
  2. Investigate — root-cause within 72 hours; preserve forensic artifacts.
  3. Notify — affected customers within 72 hours of confirmation; HIPAA-covered customers per the Breach Notification Rule (60 days of incident, with prompt good-faith effort to notify sooner).
  4. Remediate — patch + post-mortem; track durable controls in our quarterly SOC 2 prep tracker.
  5. Disclose — public post-mortem on /changelog within 14 days unless ongoing investigation requires delay.

Vulnerability disclosure

Report a vulnerability

Email security@voipy.app. We respond to confirmed reports within 48 hours and aim to patch critical issues within 7 days. Good-faith research is welcome — we will not pursue legal action for testing that meets these conditions:

PGP key + responsible-disclosure SLA: ask via the email above. Bounty program is in scoping; expect details Q3 2026.

Service availability

Production targets:

Incidents that affect customer-facing availability beyond 30 minutes are posted to /changelog.

Other questions

Pre-purchase security questionnaires (SIG, CAIQ, CAIQ Lite, custom RFPs) are completed within ~5 business days for prospective Practice and Enterprise customers. Contact us.

Privacy Policy → · Terms of Service →