Security
Security and data handling
Vexa tests with simulated callers, so no real customer call audio or PII ever enters the system. Test transcripts and scores belong to you and are not used to train any model. Written for a security reviewer, not a marketing audience.
No real call audio required
Vexa tests your voice agent using simulated callers, not recordings of real customer calls. A language model plays each caller: it holds a real conversation with your agent across voice, accent and edge case, then scores every turn on task success, tone and latency. You run thousands of test calls without collecting, storing or processing any real caller audio or personally identifiable information.
If you want to seed scenarios from real call patterns, you describe the pattern in plain text. The recording never enters the platform. This is the architecture, not a policy we could relax later by changing a setting.
Your data is yours
Your workspace, scenario suites, test transcripts and score history belong to you. We do not sell that data. We do not use it to train the models Vexa runs internally, including the speech and language models used for simulation and scoring. Anonymised, aggregate reliability and latency telemetry is kept separately and is never tied to workspace content.
You can delete individual test runs, transcripts or scenario suites from within the application at any time without contacting us.
Encryption
All traffic between your browser or client and Vexa travels over TLS 1.2 or higher. There is no unencrypted path into the application. Data at rest, including your scenario suites, agent configurations, test transcripts and score history, is encrypted with AES-256 across all storage layers. Encryption keys are managed per workspace.
Sub-processors and model providers
Vexa is model-agnostic. Its simulation and scoring pipeline routes across configurable speech-to-text, text-to-speech and language model providers. The content sent to those providers is synthetic: the simulated transcript of a test call, not real caller audio or customer data. Your workspace metadata, account information and score history are not sent to model providers.
Vexa uses sub-processors in three categories:
- Speech and language model providers. Simulation and scoring tasks route across a set of configurable providers. On the Scale plan, customers can restrict which providers the pipeline uses or bring their own. Content sent is synthetic test material only, not real caller audio or PII.
- Cloud hosting. Application infrastructure, object storage and databases run on a major US cloud provider in US regions. Test traffic and transcripts do not leave the United States on standard plans.
- Email and alerting. Regression alerts, deploy notifications and account emails are delivered via a third-party transactional email provider.
Customers who need a named sub-processor list may request it from security@vexavoice.tech. We provide advance notice of material changes to the sub-processor list.
Access control
All plans support role-based access within a workspace. Team members can be invited by email and removed from workspace settings at any time. Roles cover read-only access to scores and transcripts, write access to scenario suites and agent configurations, and admin access to billing, seats and SSO settings.
On the Scale plan, workspace administrators can enforce SAML 2.0 single sign-on against your identity provider. Deprovisioning a user in your IdP immediately terminates their Vexa access without a separate step. Audit logs covering scenario changes, deploy-gate configuration, seat changes and admin actions are available on Scale and can be exported in JSON format.
Vexa staff do not have standing read access to customer workspaces. Any elevated access for support or debugging requires an explicit, time-bounded grant, approved by a second staff member and reviewed after the fact.
Data residency and self-host
On standard plans, workspace data and test traffic are held in US regions. The Scale plan supports data residency configuration and a fully self-hosted deployment in your own cloud or VPC, so test transcripts and scores never leave your environment. Talk to sales to scope it.
Retention and deletion
Workspace data is retained while your account is active. If you close your account or submit a deletion request to security@vexavoice.tech, we delete your workspace data within 30 days and send written confirmation on completion. Backups containing your data are rotated out within the same window.
Responsible disclosure
If you find a security vulnerability in Vexa, please send details to security@vexavoice.tech. We acknowledge every report within one business day, provide status updates at 30-day intervals, and aim to resolve confirmed issues within 90 days. We do not take legal action against researchers who disclose in good faith and give us reasonable time to respond before publishing.
We do not yet offer a formal bug bounty programme. We appreciate every report and acknowledge meaningful contributions publicly where the researcher consents.
Compliance posture
SOC 2 Type II is in progress with an accredited third-party auditor. We will share the completed report with customers on request once it is issued. Current controls documentation is available on request from security@vexavoice.tech.
Quick facts
- Data residency
- United States
- Encryption in transit
- TLS 1.2+
- Encryption at rest
- AES-256
- SSO / SAML 2.0
- Scale plan
- Audit logs
- Scale plan
- SOC 2 Type II
- In progress
- Sub-processors
- Listed below
- Data deletion
- On request, 30 days
SOC 2 Type II is in progress with an accredited third-party auditor. We will share the completed report with customers on request once issued. Current controls documentation is available on request.
Questions not answered here? security@vexavoice.tech
Security reports and vulnerability disclosure: security@vexavoice.tech. General enquiries: contact form. Effective date: July 22, 2026.