Security
Your conversations stay yours.
QuorumVoice records and transcribes your organization’s calls, and keeps its texts, emails and meetings in one place. Here is how that is protected today, and our plan for an independent SOC 2 Type II report.
Encryption
At rest and in transit
AES-256 at rest for our database, files and backups; TLS between you, the app and our providers
Isolation
Per organization
Row-level security on every application table
SOC 2 Type II
Report targeted 2027
Program planned for February 2027; no SOC 2 report yet
What’s in place today
Each line below describes how the service works today, not a plan.
Encryption
- Your database, stored files and database backups are encrypted at rest with AES-256 by our database provider, Supabase.
- Traffic between your browser or phone and QuorumVoice, and between QuorumVoice and the services it uses, is encrypted in transit with TLS. Calls and texts that cross the public phone network are carried by the phone companies, as every call is.
- Email and meeting sign-in tokens, tax IDs, and number-porting account numbers and PINs are encrypted a second time with Supabase Vault, whose key is kept outside the database.
- Call recordings, voicemails, meeting recordings and photos sent in texts and team messages are kept in private storage and opened through signed links, not public file addresses. Profile and contact pictures are the exception: they are served publicly.
Keeping organizations apart
- Every table in our application database has row-level security switched on, and a new one without it fails our automated checks.
- Every database function that takes an organization’s ID checks that the person asking belongs to that organization.
- Every night an automated check against production confirms that signed-out visitors can reach only the public pieces we have deliberately opened — the blog, FAQs and invitation links — and that every application table still has row-level security on.
Who can see what
- Owners and admins control your organization’s settings, phone lines and team; other members work with your organization’s communications but cannot change those settings.
- Inside the app, staff tools work only for members of our one designated internal organization.
- Sensitive staff actions — granting or removing staff access, changing plan pricing and features, ordering or releasing phone numbers, and number-porting decisions — are written to an audit log.
- When an organization leaves, one deletion process removes its communications, contacts, recordings and message photos from our database and file storage.
How we ship
- Every push to our code repositories is scanned for leaked passwords and keys, and developers’ machines scan again before pushing.
- Code analysis and dependency vulnerability checks run on every push.
- Every database migration we commit is checked against security rules — row-level security on new tables, and no access for signed-out visitors unless deliberately allowed and listed — and the nightly production check catches what slips past.
- Every automated check in our build pipeline reports to an internal security board, and a new failure alerts us right away.
Connections to other services
- Your email and meeting accounts connect through their own sign-in (OAuth); we never see or store the passwords for those accounts.
- Summaries, search and Ask Quill reach AI models through Vercel’s AI gateway — no Anthropic or OpenAI keys live in the app.
Calling and texting safeguards
- Inbound calls to your QuorumVoice numbers play a recording notice before the call is connected and recorded.
- A STOP reply, or a plain request like “stop texting me”, opts that number out of your organization’s texts right away, and it stays opted out until the person texts START or another opt-in keyword.
- Business texting runs on registered 10DLC campaigns, as US carriers require.
- When Quill, our AI receptionist, answers a call, it texts the caller only if their number has been verified and has agreed to messages; the verification code is the one exception. If an organization turns on Quill for texting, Quill also replies to people who text that line first.
SOC 2 Type II
Our road to an independent audit
SOC 2 is an examination, defined by the AICPA, of how a company protects its customers’ data. A Type II report goes further than a snapshot: an independent CPA firm tests whether the controls actually worked over months.
We do not have a SOC 2 report yet. SOC 2 is an auditor’s report, not a certification, and we won’t claim one until an auditor has issued it. The dates below are targets and may change.
- Jul 2026Done
Security hardening
Vault encryption for sign-in tokens and tax IDs, locked-down scheduled jobs, a staff audit log, an organization-deletion process, and a written backup-and-restore runbook.
- Sep 2026Done
A scanned release pipeline
Secret scanning, code analysis and dependency checks on every push, security checks on every committed database migration, a nightly production probe, and one board that tracks them all.
- Feb 2027Planned
SOC 2 program begins
We plan to connect our infrastructure to a compliance-automation platform — we have selected LowerPlane — for continuous control monitoring, and assess ourselves against the SOC 2 criteria.
- Feb – Mar 2027Planned
Close the gaps
Planned: written security policies, scheduled access reviews, security training, and a documented incident-response plan.
- Mar 2027Planned
An independent auditor
We plan to engage a licensed CPA firm to examine our controls.
- Apr – Jun 2027Planned
Observation window
A planned window of at least three months in which our controls run and evidence is collected — the period a Type II report tests.
- Jul 2027Planned
Audit fieldwork
The auditor tests what the controls actually did over that window.
- Aug 2027Target
First SOC 2 Type II report
Planned scope: security, availability and confidentiality. We intend to share the report with customers and prospects under NDA.
Built on independently audited providers
The main services that store or process your data, what each one does, and the independent reports they hold. Our Master Service Agreement lists our sub-processors and the terms that bind them.
| Provider | What it does for you | Independent report |
|---|---|---|
| Supabase | Database, sign-in and file storage (United States) | SOC 2 Type II |
| Vercel | Application hosting and AI gateway | SOC 2 Type II |
| Telnyx | Phone calls, texts and the AI receptionist | SOC 2 Type II (voice and messaging) |
| Deepgram | Call transcription | SOC 2 Type II |
| Anthropic | Summaries, categories and Ask Quill | SOC 2 Type II |
| OpenAI | Search embeddings | SOC 2 Type II |
| Microsoft Azure · Google Cloud | Alternate hosts for the same AI models, when the AI gateway routes around an outage | SOC 2 Type II |
| Trigger.dev | Background processing after calls | SOC 2 Type II |
| Stripe | Payments | PCI DSS Level 1 · SOC 2 Type II |
| Resend | Account and notification emails | SOC 2 Type II |
| Sentry | Error monitoring | SOC 2 Type II |
Questions we get asked
Not yet. SOC 2 is an independent auditor’s report, not a certification, and we won’t claim one until an auditor has issued it. We plan to begin our SOC 2 program in February 2027 and are targeting our first Type II report for August 2027.
Until then, this page describes the controls in place today, our Master Service Agreement sets out our security commitments in writing, and we are glad to answer your security questionnaire.
Your database and stored files are hosted with Supabase in Amazon Web Services’ US East (N. Virginia) region, encrypted at rest. The providers listed above also process data to do their jobs; ask us if you need their processing locations.
Only staff in our internal administrator organization can open customer data in the app, and only for the purposes in our Master Service Agreement: supporting you and finding and fixing problems with the service. Sensitive staff actions are written to an audit log.
If a breach affecting your data is confirmed, we notify you within 72 hours of discovering it, as our Master Service Agreement requires.
Yes. Send it to support@quorumvoice.com and we will work through it with you.
Found a vulnerability?
Tell us privately and give us a chance to fix it before it is made public. We review the reports sent to this address and will reply to let you know we received yours.