🍁 Trust & Security

Where your data lives.
Who audits it. What laws it answers to.

Every VoiceAgents conversation — call audio, transcripts, customer records — is processed and stored in Canada, on independently audited infrastructure, under Canadian privacy law. Here's the paper trail.

The facility

151 Front Street West, Toronto

VoiceAgents runs on dedicated infrastructure at Canada's largest carrier hotel — the building where the country's ISPs, cloud providers, and content networks physically interconnect. Our data centre operator, Amanah Tech, has run this facility presence since 2001.

99.99%
Facility uptime SLA
24/7
On-site staff & CCTV
N+1
Power & cooling redundancy
100%
Data resident in Canada
Certifications & compliance

Audited controls, not promises

Certifications below are held at the infrastructure layer by our data centre operator and observed by VoiceAgents at the application layer.

Infrastructure · Audited

SOC 2 Type II

Our hosting infrastructure is SOC 2 Type II attested across security, availability, confidentiality, privacy, and processing integrity. Type II means an independent auditor tested that controls operated effectively over time — not just that they exist on paper.

Report available under NDA
Federal law · Canada

PIPEDA

The Personal Information Protection and Electronic Documents Act governs how we collect, use, and store your customers' personal information. Because your data never leaves Canada, PIPEDA and provincial privacy law are the only regimes it answers to.

Overseen by the Office of the Privacy Commissioner of Canada
Outbound · Canada

CASL

Every outbound campaign — win-back, collections reminders, review requests — runs with consent tracking built in, compliant with Canada's Anti-Spam Legislation. One demo call means one demo call.

Consent records retained and auditable per campaign
Health information: our facility operator additionally maintains PHIPA compliance (Ontario's health-privacy regime). If your business handles personal health information, talk to us about a PHIPA-aligned deployment before go-live.
Our practices

How VoiceAgents protects every conversation

Call audio and customer data encrypted in transit (TLS 1.2+) and at rest
Role-based access control — your data is visible only to accounts you authorize
Continuous network monitoring with incident detection and response procedures
Change management and configuration controls on every production system
Full call audit trail: recordings, transcripts, and outcomes, timestamped
Data deletion on request — your customers' data is yours, not ours
Bilingual (EN/FR) privacy notices available for your customers
No training of third-party foundation models on your customer data

Questions our answers didn't cover?

Security questionnaires, audit reports, data-processing agreements — we'll get you what your review needs.

Talk to us →