Enterprise-grade voice AI built on trust, security, and sovereignty.
Review Vatel AI's active security posture, SOC 2 alignment, Quebec Law 25 compliance, and data protection controls.
At Vatel AI, data privacy and security are not optional add-ons—they are fundamental to how we design, build, and operate our voice platform. Designed specifically for regulated industries, contact centers, and enterprise operations in Canada and North America, Vatel AI ensures that all active audio streams, database queries, and call transcripts are encrypted end-to-end (SSL/TLS in transit, AES-256 at rest). Hosted on secure, SOC 2 Type II-audited cloud infrastructure, Vatel AI supports customizable data retention policies for automated, scheduled data destruction, guaranteeing full alignment with Quebec's Law 25 (Loi 25), PIPEDA, HIPAA, and GDPR.
Compliance frameworks
Quebec's Law 25
Full compliance with Quebec data sovereignty rules. Explicit consent workflows, customer data isolation, and custom automated retention schedules that purge recordings and transcripts.
SOC 2 Type II
Infrastructure hosted on SOC 2 Type II-certified cloud nodes (Google Cloud & Supabase), with rigorous availability, security, and confidentiality controls.
PIPEDA (Canada)
Canadian federal privacy standard.
ISO 27001
ISMS controls, 2013 & 2022 editions.

HIPAA
Encrypted audio, BAA on request.
GDPR
Access & erasure rights, DPA with SCCs.
Core security controls
TLS
Encryption across all SIP trunks, WebSockets & REST APIs.
AES-256
Databases, audio files, and transcripts encrypted at rest.
RBAC
MFA, SSO, need-to-know staff privileges.
Isolated enterprise cloud nodes
Google Cloud & Supabase · Canada / US
Automated retention & destruction · Law 25 / HIPAAIn transit
All telephony SIP traffic, WebRTC audio streams, REST API queries, and WebSockets are encrypted using TLS 1.3 / SSL.
At rest
Database tables, conversation logs, customer records, and call audio files are encrypted using AES-256 bit encryption.
Zero model training
Our enterprise agreements with underlying LLM partners strictly prohibit training foundation models on your customer voice or text data.
Custom retention schedules
Enterprise administrators can configure custom data retention rules per agent—from 24 hours up to 2 years—after which call recordings, audio snippets, and transcripts are permanently purged from server memory.
Sensitive call handling
Audio recordings can be completely disabled for specific sensitive agents or call types (e.g., medical triage, payment confirmation) while retaining only structured metadata.
Role-based access control (RBAC)
Granular permission controls restricting access to agent configuration, transcripts, and analytics based on employee roles.
Mandatory multi-factor authentication (MFA)
Enforced across all internal administrative access and customer console accounts.
Secrets management
API keys, database credentials, and SIP tokens are managed in isolated, encrypted vaults with automated rotation.
Environment segregation
Strict separation between Development, Staging, and Production environments. Production data is never used in non-production testing.
DDoS & cloud firewalls
Protected by enterprise Web Application Firewalls (WAF) and Cloudflare rate-limiting.
Same-day rollback
Automated CI/CD pipeline allowing instant version rollback in the event of software anomalies.
Documents
SOC 2 report
Infrastructure audit
Data Processing Addendum
Includes SCCs
HIPAA BAA
Healthcare customers
Security questionnaire
Vendor assessment
Subprocessors directory
Vendors that may process customer data to operate Vatel. Locations are typical headquarters or processing regions, not a signed DPA.
| Company | Purpose | Location |
|---|---|---|
| Infrastructure | ||
| Google Cloud | Servers. | United States, Canada |
| Vercel | Hosting. LLM. | United States, Canada |
| Supabase | Authentication, database, storage. | United States, Canada |
| GitHub | Source control, CI/CD. | United States |
| Better Stack | Logging. | United States |
| Stripe | Billing. | United States |
| Resend | Email. | United States |
| Voice & audio | ||
| ElevenLabs | Voices. | United States, EU |
| Deepgram | Transcriber. | United States, EU |
| OpenAI | LLM, Voice. | United States, EU |
| AssemblyAI | Transcriber. | United States, EU |
| LLM, Transcriber, Voices. | United States, EU | |
| Gladia | Transcriber. | United States, EU |
| Soniox | Transcriber. | United States, EU |
| Speechmatics | Transcriber. | United States, EU |
| xAI | LLM, Voice. | United States, EU |
| Cartesia | Voices. | United States, EU |
| Hume AI | Voice. | United States |
| MiniMax | Voice, LLM. | China |
| Fish Audio | Voices. | China |
| Inworld AI | Voice. | United States |
| LLMs & gateways | ||
| LLM. | United States, EU | |
| OpenRouter | LLM. | United States |
| Anthropic | LLM. | United States, EU |
| Alibaba / Qwen | LLM. | China |
| Moonshot AI | LLM. | China |
| Zhipu / Z.AI | LLM. | China |
| IBM | LLM. | United States |
| DeepSeek | LLM. | China |
| Communications | ||
| Twilio | Telephony. | United States, EU |
| Customer integrations | ||
| Customer HTTP webhooks | Customer-configured endpoints. | Customer-determined |
SIP peers
SIP trunks and SBCs peered to Vatel are not Vatel-owned subprocessors unless separately contracted.
FAQ
Answers on Law 25, HIPAA BAAs, model training, and how to request SOC 2 reports or a DPA.
Vatel AI enforces privacy-by-design principles natively aligned with Law 25. All customer data, voice streams, and transcripts are encrypted in transit and at rest. Furthermore, businesses can set custom data retention rules to automatically delete transcripts and call recordings on a scheduled timeline, honoring the right to erasure and preventing unauthorized data retention.
Yes. For healthcare providers, dental networks, and medical aesthetic clinics (such as 123 Dentiste and Clinique Dominique Girard), Vatel AI provides a self-service or custom BAA to ensure full HIPAA compliance.
No, never. Our enterprise agreements with LLM and speech model providers strictly mandate zero data retention for training purposes. Your proprietary conversation data remains 100% yours.
To request formal compliance documentation, execute a Data Processing Addendum (DPA), or submit a vendor security assessment, please contact our security team at security@vatel.ai.
Request a security review
Headquarters: Devpro Digital / Vatel AI, Montreal, QC, Canada