Vatel AI
Company · Trust center

Enterprise-grade voice AI built on trust, security, and sovereignty.

Review Vatel AI's active security posture, SOC 2 alignment, Quebec Law 25 compliance, and data protection controls.

Executive summary

At Vatel AI, data privacy and security are not optional add-ons—they are fundamental to how we design, build, and operate our voice platform. Designed specifically for regulated industries, contact centers, and enterprise operations in Canada and North America, Vatel AI ensures that all active audio streams, database queries, and call transcripts are encrypted end-to-end (SSL/TLS in transit, AES-256 at rest). Hosted on secure, SOC 2 Type II-audited cloud infrastructure, Vatel AI supports customizable data retention policies for automated, scheduled data destruction, guaranteeing full alignment with Quebec's Law 25 (Loi 25), PIPEDA, HIPAA, and GDPR.

Regulatory standards

Compliance frameworks

Quebec's Law 25

Full compliance with Quebec data sovereignty rules. Explicit consent workflows, customer data isolation, and custom automated retention schedules that purge recordings and transcripts.

SOC 2 Type II

Infrastructure hosted on SOC 2 Type II-certified cloud nodes (Google Cloud & Supabase), with rigorous availability, security, and confidentiality controls.

PIPEDA (Canada)

Canadian federal privacy standard.

ISO 27001

ISMS controls, 2013 & 2022 editions.

HIPAA

Encrypted audio, BAA on request.

GDPR

Access & erasure rights, DPA with SCCs.

Platform architecture

Core security controls

Data in transit

TLS

Encryption across all SIP trunks, WebSockets & REST APIs.

Data at rest

AES-256

Databases, audio files, and transcripts encrypted at rest.

Access & identity

RBAC

MFA, SSO, need-to-know staff privileges.

Isolated enterprise cloud nodes

Google Cloud & Supabase · Canada / US

Automated retention & destruction · Law 25 / HIPAA

In transit

All telephony SIP traffic, WebRTC audio streams, REST API queries, and WebSockets are encrypted using TLS 1.3 / SSL.

At rest

Database tables, conversation logs, customer records, and call audio files are encrypted using AES-256 bit encryption.

Zero model training

Our enterprise agreements with underlying LLM partners strictly prohibit training foundation models on your customer voice or text data.

Custom retention schedules

Enterprise administrators can configure custom data retention rules per agent—from 24 hours up to 2 years—after which call recordings, audio snippets, and transcripts are permanently purged from server memory.

Sensitive call handling

Audio recordings can be completely disabled for specific sensitive agents or call types (e.g., medical triage, payment confirmation) while retaining only structured metadata.

Role-based access control (RBAC)

Granular permission controls restricting access to agent configuration, transcripts, and analytics based on employee roles.

Mandatory multi-factor authentication (MFA)

Enforced across all internal administrative access and customer console accounts.

Secrets management

API keys, database credentials, and SIP tokens are managed in isolated, encrypted vaults with automated rotation.

Environment segregation

Strict separation between Development, Staging, and Production environments. Production data is never used in non-production testing.

DDoS & cloud firewalls

Protected by enterprise Web Application Firewalls (WAF) and Cloudflare rate-limiting.

Same-day rollback

Automated CI/CD pipeline allowing instant version rollback in the event of software anomalies.

For procurement

Documents

SOC 2 report

Infrastructure audit

Data Processing Addendum

Includes SCCs

HIPAA BAA

Healthcare customers

Security questionnaire

Vendor assessment

Third parties

Subprocessors directory

Vendors that may process customer data to operate Vatel. Locations are typical headquarters or processing regions, not a signed DPA.

CompanyPurposeLocation
Infrastructure
Google CloudServers.United States, Canada
VercelHosting. LLM.United States, Canada
SupabaseAuthentication, database, storage.United States, Canada
GitHubSource control, CI/CD.United States
Better StackLogging.United States
StripeBilling.United States
ResendEmail.United States
Voice & audio
ElevenLabsVoices.United States, EU
DeepgramTranscriber.United States, EU
OpenAILLM, Voice.United States, EU
AssemblyAITranscriber.United States, EU
GoogleLLM, Transcriber, Voices.United States, EU
GladiaTranscriber.United States, EU
SonioxTranscriber.United States, EU
SpeechmaticsTranscriber.United States, EU
xAILLM, Voice.United States, EU
CartesiaVoices.United States, EU
Hume AIVoice.United States
MiniMaxVoice, LLM.China
Fish AudioVoices.China
Inworld AIVoice.United States
LLMs & gateways
GoogleLLM.United States, EU
OpenRouterLLM.United States
AnthropicLLM.United States, EU
Alibaba / QwenLLM.China
Moonshot AILLM.China
Zhipu / Z.AILLM.China
IBMLLM.United States
DeepSeekLLM.China
Communications
TwilioTelephony.United States, EU
Customer integrations
Customer HTTP webhooksCustomer-configured endpoints.Customer-determined

SIP peers

SIP trunks and SBCs peered to Vatel are not Vatel-owned subprocessors unless separately contracted.

Trust & security

FAQ

Answers on Law 25, HIPAA BAAs, model training, and how to request SOC 2 reports or a DPA.

Vatel AI enforces privacy-by-design principles natively aligned with Law 25. All customer data, voice streams, and transcripts are encrypted in transit and at rest. Furthermore, businesses can set custom data retention rules to automatically delete transcripts and call recordings on a scheduled timeline, honoring the right to erasure and preventing unauthorized data retention.

Yes. For healthcare providers, dental networks, and medical aesthetic clinics (such as 123 Dentiste and Clinique Dominique Girard), Vatel AI provides a self-service or custom BAA to ensure full HIPAA compliance.

No, never. Our enterprise agreements with LLM and speech model providers strictly mandate zero data retention for training purposes. Your proprietary conversation data remains 100% yours.

To request formal compliance documentation, execute a Data Processing Addendum (DPA), or submit a vendor security assessment, please contact our security team at security@vatel.ai.

Request documents

Tell us what you need and where to send it.

Documents

Request a security review

Headquarters: Devpro Digital / Vatel AI, Montreal, QC, Canada