Security
A practical security approach for business communication
Security capabilities are designed to be documented during onboarding and depend on the final deployment, telephony, AI, calendar, CRM and notification providers.
Data flow overview
- Caller
- Telephony provider
- AI/voice workflow
- SimplyVoxa application
- Calendar/CRM/notification provider
Text alternative: caller data flows from the caller to a telephony provider, then the AI voice workflow, then the SimplyVoxa application, then configured calendar, CRM or notification providers.
Security overview
Security approach
Designed to keep caller and lead information limited, validated and accessible only through configured server-side paths.
Encryption in transit
Production deployments should use HTTPS and encrypted provider connections.
Storage controls
Lead storage can be configured through Supabase/PostgreSQL with RLS and server-side inserts.
Access controls
Admin access is designed around Supabase Auth, allowlisted emails and server-side authorization.
Secrets management
Server-only variables are kept out of client bundles and documented in environment setup.
Logging and monitoring
Errors should be logged without complete personal data. Audit events are recorded for sensitive admin actions.
Backups and recovery
Backup and recovery controls depend on the selected database and hosting configuration.
Vendor review
Telephony, AI, hosting, database, email and CRM vendors should be documented during onboarding.
Retention and deletion
Retention can be configured, with archive and permanent deletion procedures documented.
Incident response
Incident processes should be confirmed before production launch.
Responsible disclosure
Security reports can be sent to contact@simplyvoxa.com.
Client responsibilities
Customers must approve knowledge, disclosures, escalation rules and integration access.
SimplyVoxa does not claim SOC 2, ISO 27001, GDPR, HIPAA, DPDP, PCI or similar certification on this website.
Review security during onboarding
We will document the controls, vendors and responsibilities included in the final deployment.
