Trust Center
How Vagary Voice handles your data, who our subprocessors are, and the security controls that protect the platform. Everything here reflects our real infrastructure — no claims we can't back.
Compliance posture
SOC 2
Type 1 controls in placeSOC 2 Type 1 control objectives (CC6.1, CC6.6, CC6.7, CC7.2, CC7.3, A1.2, C1.1) are implemented at the API substrate and verified in our internal security audit. A Type II attestation (independent, over-time) is not yet obtained.
OWASP Top 10
Addressed at substrateA01–A10 reviewed and closed at the V1 API substrate level (auth, injection, access control, misconfiguration) as part of the vertical security audit.
GDPR / CCPA
Data-subject controlsConsent capture and erasure-by-consent are implemented in the data path (D22 consent gate + PII-safe handling). Formal DPA templates are available on request.
HIPAA
Not offeredWe do not currently offer a BAA or represent the platform as HIPAA-compliant. Do not send PHI through the platform.
We state only what we can substantiate. If a certificate or attestation is not listed here, we do not hold it.
Security controls
Encryption in transit
All public traffic is served over TLS (Cloudflare edge + Traefik on the compute host). Provider API calls are HTTPS-only.
Secrets management
Secrets (provider keys, DB credentials) live only in Infisical — never committed to source. Rendered to the runtime at deploy time.
Authentication
API access uses RS256 (asymmetric) JWTs and per-org API keys. Tenant data is isolated at the database layer via row-level security (RLS).
Observability & error tracking
Errors flow to a self-hosted GlitchTip (single error store — no third-party dual-reporting). Logs and metrics via Loki/Prometheus/Grafana.
Backups
Stateful volumes (TimescaleDB) are backed up with restic (host-level). Backup tier T1 for the stateful data path.
Infrastructure
Runs on a dedicated VPS (vagary-compute-1) via docker-compose. Single-region today; multi-region is on the roadmap, not yet wired.
Subprocessors
The third parties that process data on our behalf to deliver the voice platform. Voice/text content is sent transiently for real-time processing and is not retained by these providers beyond their own operational needs.
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| OpenAI | LLM inference + text-to-speech | Conversation text (transient) | US |
| Anthropic | LLM inference (dialog turns) | Conversation text (transient) | US |
| Deepgram | Speech-to-text | Call audio (transient) | US |
| ElevenLabs | Text-to-speech synthesis | Response text (transient) | US |
| Google (Gemini) | LLM/TTS (optional fallback provider) | Conversation text (transient) | US |
| Stripe | Billing & payments | Billing metadata (no card data stored by us) | US/EU |
| Cloudflare | DNS, TLS edge, DDoS/WAF | Request metadata | Global edge |
| Hostinger (VPS) | Compute host (vagary-compute-1) | Application + database volumes | EU |
System Status
Live uptime and incident history for all Vagary Voice services on our public status page.
status.chinmayramraika.inContact Support
Security disclosures, data requests (access/erasure), or product help — reach the team and we'll route your request.