Legal · Security
Security & SOC 2 Readiness
SOC 2 attestation: in progress
Audit pendingQuorumVoice is actively pursuing a SOC 2 Type II attestation. Our security controls are continuously monitored through LowerPlane, our compliance automation platform, which collects evidence across our infrastructure, access controls, and vendor management around the clock. The formal SOC 2 examination is performed by an independent CPA firm; until that report is issued we do not claim SOC 2 certification — this page describes the controls already in place and our path to attestation. When the report is available, we will share it with customers and prospects under NDA on request.
What SOC 2 Means for You
SOC 2 is an independent examination, defined by the AICPA, of how a service provider protects customer data against the Trust Services Criteria — security, availability, and confidentiality. For a platform that records calls, stores transcripts, and handles your organization's communications, that scrutiny is the point: our customers in community management, education, and nonprofit sectors are trusted with their own communities' data, and they need vendors who can prove — not just promise — that it is handled properly.
Controls Already in Place
Encryption everywhere
Customer data is encrypted at rest (AES-256) and in transit (TLS 1.2+). OAuth tokens and sensitive identifiers are additionally encrypted with vault-level encryption, and call recordings live in private storage reachable only through time-limited signed URLs.
Tenant isolation at the database layer
Every table enforces row-level security keyed to your organization. Isolation is not an application convention — it is enforced by the database on every query, so one organization can never read another’s data.
Least-privilege access
Role-based access control (owner, admin, member, viewer) governs every surface, and privileged platform access is restricted to a designated super-admin organization. Access to production data is limited to authorized personnel on a need-to-know basis.
Hardened integrations
Every inbound webhook is signature-verified and idempotent. All AI processing runs through a gateway with no provider API keys in the application, and customer data is never used to train AI models.
Accountable data lifecycle
Customers own their data, can export it at any time, and receive a defined export window at termination followed by deletion. Confirmed breaches are notified within 72 hours under our Master Service Agreement.
Continuous Monitoring with LowerPlane
Rather than treating compliance as an annual scramble, our program runs on continuous monitoring. LowerPlane connects directly to our infrastructure and tooling and automatically tracks the state of our controls against SOC 2's 64 controls, including:
- Infrastructure configuration and encryption posture across our cloud providers
- Access reviews — who has access to what, flagged the moment it drifts
- Vendor management and sub-processor risk tracking
- Personnel security requirements, including security training and device policies
- Evidence collection for the independent audit, gathered automatically as we operate
This means the controls described on this page aren't point-in-time claims — they are checked continuously, and a control that regresses surfaces as an alert, not a finding in next year's audit.
Built on Audited Infrastructure
QuorumVoice is built on infrastructure providers that hold their own independent security attestations, so your data is protected by audited controls at every layer beneath us:
| Provider | Role | Attestations |
|---|---|---|
| Supabase | Database, auth & storage | SOC 2 Type II |
| Vercel | Hosting & AI gateway | SOC 2 Type II |
| Telnyx | Telephony & SMS | SOC 2 Type II |
| Stripe | Payments | PCI DSS Level 1 · SOC 2 |
| Deepgram | Transcription | SOC 2 Type II |
| Anthropic | AI classification | SOC 2 Type II |
| OpenAI | Embeddings | SOC 2 Type II |
| Resend | Transactional email | SOC 2 Type II |
The full sub-processor list, including the scope of each provider's access, is in our Master Service Agreement and Privacy Policy.
Security Reviews & Questionnaires
Evaluating QuorumVoice for your organization? We're glad to support your diligence process: security questionnaires, architecture questions, and — once issued — our SOC 2 report under NDA. If you believe you've found a security vulnerability in QuorumVoice, please report it to the same address; we investigate every report and will acknowledge yours promptly.
Contact security@quorumvoice.com.
Related: Master Service Agreement · Privacy Policy · 10DLC Registration Guide