Trust Center

How Vagary Voice handles your data, who our subprocessors are, and the security controls that protect the platform. Everything here reflects our real infrastructure — no claims we can't back.

Compliance posture

SOC 2

Type 1 controls in place

SOC 2 Type 1 control objectives (CC6.1, CC6.6, CC6.7, CC7.2, CC7.3, A1.2, C1.1) are implemented at the API substrate and verified in our internal security audit. A Type II attestation (independent, over-time) is not yet obtained.

OWASP Top 10

Addressed at substrate

A01–A10 reviewed and closed at the V1 API substrate level (auth, injection, access control, misconfiguration) as part of the vertical security audit.

GDPR / CCPA

Data-subject controls

Consent capture and erasure-by-consent are implemented in the data path (D22 consent gate + PII-safe handling). Formal DPA templates are available on request.

HIPAA

Not offered

We do not currently offer a BAA or represent the platform as HIPAA-compliant. Do not send PHI through the platform.

We state only what we can substantiate. If a certificate or attestation is not listed here, we do not hold it.

Security controls

Encryption in transit

All public traffic is served over TLS (Cloudflare edge + Traefik on the compute host). Provider API calls are HTTPS-only.

Secrets management

Secrets (provider keys, DB credentials) live only in Infisical — never committed to source. Rendered to the runtime at deploy time.

Authentication

API access uses RS256 (asymmetric) JWTs and per-org API keys. Tenant data is isolated at the database layer via row-level security (RLS).

Observability & error tracking

Errors flow to a self-hosted GlitchTip (single error store — no third-party dual-reporting). Logs and metrics via Loki/Prometheus/Grafana.

Backups

Stateful volumes (TimescaleDB) are backed up with restic (host-level). Backup tier T1 for the stateful data path.

Infrastructure

Runs on a dedicated VPS (vagary-compute-1) via docker-compose. Single-region today; multi-region is on the roadmap, not yet wired.

Subprocessors

The third parties that process data on our behalf to deliver the voice platform. Voice/text content is sent transiently for real-time processing and is not retained by these providers beyond their own operational needs.

SubprocessorPurposeData processedRegion
OpenAILLM inference + text-to-speechConversation text (transient)US
AnthropicLLM inference (dialog turns)Conversation text (transient)US
DeepgramSpeech-to-textCall audio (transient)US
ElevenLabsText-to-speech synthesisResponse text (transient)US
Google (Gemini)LLM/TTS (optional fallback provider)Conversation text (transient)US
StripeBilling & paymentsBilling metadata (no card data stored by us)US/EU
CloudflareDNS, TLS edge, DDoS/WAFRequest metadataGlobal edge
Hostinger (VPS)Compute host (vagary-compute-1)Application + database volumesEU

System Status

Live uptime and incident history for all Vagary Voice services on our public status page.

status.chinmayramraika.in

Contact Support

Security disclosures, data requests (access/erasure), or product help — reach the team and we'll route your request.