Security

Your conversations stay yours.

QuorumVoice records and transcribes your organization’s calls, and keeps its texts, emails and meetings in one place. Here is how that is protected today, and our plan for an independent SOC 2 Type II report.

Encryption

At rest and in transit

AES-256 at rest for our database, files and backups; TLS between you, the app and our providers

Isolation

Per organization

Row-level security on every application table

SOC 2 Type II

Report targeted 2027

Program planned for February 2027; no SOC 2 report yet

What’s in place today

Each line below describes how the service works today, not a plan.

Encryption

  • Your database, stored files and database backups are encrypted at rest with AES-256 by our database provider, Supabase.
  • Traffic between your browser or phone and QuorumVoice, and between QuorumVoice and the services it uses, is encrypted in transit with TLS. Calls and texts that cross the public phone network are carried by the phone companies, as every call is.
  • Email and meeting sign-in tokens, tax IDs, and number-porting account numbers and PINs are encrypted a second time with Supabase Vault, whose key is kept outside the database.
  • Call recordings, voicemails, meeting recordings and photos sent in texts and team messages are kept in private storage and opened through signed links, not public file addresses. Profile and contact pictures are the exception: they are served publicly.

Keeping organizations apart

  • Every table in our application database has row-level security switched on, and a new one without it fails our automated checks.
  • Every database function that takes an organization’s ID checks that the person asking belongs to that organization.
  • Every night an automated check against production confirms that signed-out visitors can reach only the public pieces we have deliberately opened — the blog, FAQs and invitation links — and that every application table still has row-level security on.

Who can see what

  • Owners and admins control your organization’s settings, phone lines and team; other members work with your organization’s communications but cannot change those settings.
  • Inside the app, staff tools work only for members of our one designated internal organization.
  • Sensitive staff actions — granting or removing staff access, changing plan pricing and features, ordering or releasing phone numbers, and number-porting decisions — are written to an audit log.
  • When an organization leaves, one deletion process removes its communications, contacts, recordings and message photos from our database and file storage.

How we ship

  • Every push to our code repositories is scanned for leaked passwords and keys, and developers’ machines scan again before pushing.
  • Code analysis and dependency vulnerability checks run on every push.
  • Every database migration we commit is checked against security rules — row-level security on new tables, and no access for signed-out visitors unless deliberately allowed and listed — and the nightly production check catches what slips past.
  • Every automated check in our build pipeline reports to an internal security board, and a new failure alerts us right away.

Connections to other services

  • Your email and meeting accounts connect through their own sign-in (OAuth); we never see or store the passwords for those accounts.
  • Summaries, search and Ask Quill reach AI models through Vercel’s AI gateway — no Anthropic or OpenAI keys live in the app.

Calling and texting safeguards

  • Inbound calls to your QuorumVoice numbers play a recording notice before the call is connected and recorded.
  • A STOP reply, or a plain request like “stop texting me”, opts that number out of your organization’s texts right away, and it stays opted out until the person texts START or another opt-in keyword.
  • Business texting runs on registered 10DLC campaigns, as US carriers require.
  • When Quill, our AI receptionist, answers a call, it texts the caller only if their number has been verified and has agreed to messages; the verification code is the one exception. If an organization turns on Quill for texting, Quill also replies to people who text that line first.

SOC 2 Type II

Our road to an independent audit

SOC 2 is an examination, defined by the AICPA, of how a company protects its customers’ data. A Type II report goes further than a snapshot: an independent CPA firm tests whether the controls actually worked over months.

We do not have a SOC 2 report yet. SOC 2 is an auditor’s report, not a certification, and we won’t claim one until an auditor has issued it. The dates below are targets and may change.

  1. Jul 2026Done

    Security hardening

    Vault encryption for sign-in tokens and tax IDs, locked-down scheduled jobs, a staff audit log, an organization-deletion process, and a written backup-and-restore runbook.

  2. Sep 2026Done

    A scanned release pipeline

    Secret scanning, code analysis and dependency checks on every push, security checks on every committed database migration, a nightly production probe, and one board that tracks them all.

  3. Feb 2027Planned

    SOC 2 program begins

    We plan to connect our infrastructure to a compliance-automation platform — we have selected LowerPlane — for continuous control monitoring, and assess ourselves against the SOC 2 criteria.

  4. Feb – Mar 2027Planned

    Close the gaps

    Planned: written security policies, scheduled access reviews, security training, and a documented incident-response plan.

  5. Mar 2027Planned

    An independent auditor

    We plan to engage a licensed CPA firm to examine our controls.

  6. Apr – Jun 2027Planned

    Observation window

    A planned window of at least three months in which our controls run and evidence is collected — the period a Type II report tests.

  7. Jul 2027Planned

    Audit fieldwork

    The auditor tests what the controls actually did over that window.

  8. Aug 2027Target

    First SOC 2 Type II report

    Planned scope: security, availability and confidentiality. We intend to share the report with customers and prospects under NDA.

Built on independently audited providers

The main services that store or process your data, what each one does, and the independent reports they hold. Our Master Service Agreement lists our sub-processors and the terms that bind them.

ProviderWhat it does for youIndependent report
SupabaseDatabase, sign-in and file storage (United States)SOC 2 Type II
VercelApplication hosting and AI gatewaySOC 2 Type II
TelnyxPhone calls, texts and the AI receptionistSOC 2 Type II (voice and messaging)
DeepgramCall transcriptionSOC 2 Type II
AnthropicSummaries, categories and Ask QuillSOC 2 Type II
OpenAISearch embeddingsSOC 2 Type II
Microsoft Azure · Google CloudAlternate hosts for the same AI models, when the AI gateway routes around an outageSOC 2 Type II
Trigger.devBackground processing after callsSOC 2 Type II
StripePaymentsPCI DSS Level 1 · SOC 2 Type II
ResendAccount and notification emailsSOC 2 Type II
SentryError monitoringSOC 2 Type II

Questions we get asked

Not yet. SOC 2 is an independent auditor’s report, not a certification, and we won’t claim one until an auditor has issued it. We plan to begin our SOC 2 program in February 2027 and are targeting our first Type II report for August 2027.

Until then, this page describes the controls in place today, our Master Service Agreement sets out our security commitments in writing, and we are glad to answer your security questionnaire.

Your database and stored files are hosted with Supabase in Amazon Web Services’ US East (N. Virginia) region, encrypted at rest. The providers listed above also process data to do their jobs; ask us if you need their processing locations.

Only staff in our internal administrator organization can open customer data in the app, and only for the purposes in our Master Service Agreement: supporting you and finding and fixing problems with the service. Sensitive staff actions are written to an audit log.

If a breach affecting your data is confirmed, we notify you within 72 hours of discovering it, as our Master Service Agreement requires.

Yes. Send it to support@quorumvoice.com and we will work through it with you.

Found a vulnerability?

Tell us privately and give us a chance to fix it before it is made public. We review the reports sent to this address and will reply to let you know we received yours.

support@quorumvoice.com