> Markdown rendition of https://www.voiceflow.com/legal/security ("Security | Voiceflow"). Canonical page: https://www.voiceflow.com/legal/security · All pages: https://www.voiceflow.com/llms.txt

Security

# Security at Voiceflow

Our top priority is delivering a performant platform that keeps customer data safe and end-user interactions secure.

## Secure and scalable agents

Teams trust Voiceflow to build and deploy AI automation use cases securely and at scale.

### Reliability

Enterprise-grade reliability with 24x7 monitoring, multi-AZ cloud infrastructure, and annually tested disaster recovery. Built on AWS and GCP with isolated environments and Infrastructure as Code for consistent, resilient operations.

### Security

Strong security foundations with encrypted credential storage (bcrypt), audit logging and alerting, granular access controls, continuous updates, and full project history tracking with rollback capability.

### Data

Data is protected with strong encryption at rest using customer-managed keys, securely backed up across regions, and stored in highly available multi-AZ databases with point-in-time recovery.

### Network

Network security is enforced through a CDN-backed WAF and DDoS protection, end-to-end encryption in transit with TLS and mTLS, and a segmented, firewalled architecture that strictly controls service-to-service communication.

### Organizational

Organizational security is reinforced through employee background checks, ongoing security training, least-privilege access controls, comprehensive audit logging, and regularly tested business continuity and disaster recovery plans.

### Application

Application security is maintained through automated and manual code reviews, continuous vulnerability scanning, regular external penetration testing, and enterprise-grade access controls including SSO.

Security

## Purpose-built for enterprise scale

Production volume, and the certifications to run it on regulated data.

99.95

%

Agent uptime

50

ms

Voiceflow latency

300

K

Messages per minute scale

[![AICPA SOC 2 badge](https://www.voiceflow.com/images/Badge.svg)SOC-2 Type IIAudited for data privacy, processing integrity, and confidentiality.](https://trust.voiceflow.com/)

[![ISO 27001 certification badge](https://www.voiceflow.com/images/ISO.avif) ISO/IEC 27001:2022Certified information security management.](https://trust.voiceflow.com/)

[![GDPR compliance badge](https://www.voiceflow.com/images/GDPR.svg) GDPR CompliantPersonal data stays personal, with granular permissions.](https://trust.voiceflow.com/)

[![HIPAA compliance badge](https://www.voiceflow.com/images/hipaa.avif) HIPAA CompliantProtected health information kept secure.](https://trust.voiceflow.com/)

![bg image](https://www.voiceflow.com/images/frame-2147241001-18.svg)

## Voiceflow bug bounty

If you discover a potential security vulnerability, please email [security@voiceflow.com](mailto:security@voiceflow.com). Eligible submissions may qualify for our bug bounty program.

Voiceflow values the contributions of the security research community in helping us maintain a safe and secure platform. We provide safe harbor for good-faith security research conducted in accordance with this Vulnerability Disclosure Policy. This means that if you comply with the guidelines set forth in this policy, Voiceflow will not initiate legal action against you under the Computer Fraud and Abuse Act (CFAA), the Digital Millennium Copyright Act (DMCA), or similar laws in other jurisdictions. We ask that you refrain from publicly disclosing any potential vulnerability until our security team has had the opportunity to review and address it.
