> Markdown rendition of https://www.voiceflow.com/security ("Security | Voiceflow"). Canonical page: https://www.voiceflow.com/security · All pages: https://www.voiceflow.com/llms.txt

[Own your CXMeet your AI co-pilotOct 6Save your spotSave your spot](https://www.voiceflow.com/events/own-your-cx)

Security

# Security at Voiceflow

Our top priority is delivering a performant platform that keeps customer data safe and end-user interactions secure.

Trust Center

Reports, certificates, and security documentation

[Visit Trust Center](https://trust.voiceflow.com/)

## Certifications and compliance

Explore our compliance frameworks, supporting documentation, and what they mean for your team.

###

[SOC 2 Type IIView compliance](https://www.voiceflow.com/compliance/soc-2)

###

[ISO 27001View compliance](https://www.voiceflow.com/compliance/iso-27001)

###

[GDPRView compliance](https://www.voiceflow.com/compliance/gdpr)

###

[HIPAAView compliance](https://www.voiceflow.com/compliance/hipaa)

## How we protect your data

### Data protection

Data is protected with strong encryption at rest using customer-managed keys, securely backed up across regions, and stored in highly available multi-AZ databases with point-in-time recovery.

### Access and application security

Application security is maintained through automated and manual code reviews, continuous vulnerability scanning, regular external penetration testing, and enterprise-grade access controls including SSO.

### Infrastructure and reliability

Enterprise-grade reliability with 24x7 monitoring, multi-AZ cloud infrastructure, and annually tested disaster recovery. Built on AWS and GCP with isolated environments and Infrastructure as Code for consistent, resilient operations.

### Network security

Network security is enforced through a CDN-backed WAF and DDoS protection, end-to-end encryption in transit with TLS and mTLS, and a segmented, firewalled architecture that strictly controls service-to-service communication.

### Security operations

Strong security foundations with encrypted credential storage (bcrypt), audit logging and alerting, granular access controls, continuous updates, and full project history tracking with rollback capability.

### Organizational security

Organizational security is reinforced through employee background checks, ongoing security training, least-privilege access controls, comprehensive audit logging, and regularly tested business continuity and disaster recovery plans.

AI data privacy

## Voiceflow does not use customer data to train any machine learning or AI models.

Customer data is only used to provide and operate the service. Any model providers integrated through Voiceflow (e.g., OpenAI, Anthropic, Google) are configured with zero data retention and do not use submitted data for training.

## Security resources

[Trust CenterReports, certificates, and security documentation↗](https://trust.voiceflow.com/) [Data Processing Addendum How personal data is processed ↗](https://www.voiceflow.com/legal/dpa) [Privacy policy How we handle personal information ↗](https://www.voiceflow.com/privacy) [GDPR information Data protection and individual rights ↗](https://www.voiceflow.com/legal/gdpr) [Service status Current platform status ↗](https://status.voiceflow.com/)

## Responsible disclosure

If you discover a potential security vulnerability, please email [security@voiceflow.com](mailto:security@voiceflow.com). Eligible submissions may qualify for our bug bounty program.

Voiceflow values the contributions of the security research community in helping us maintain a safe and secure platform. We provide safe harbor for good-faith security research conducted in accordance with this Vulnerability Disclosure Policy. This means that if you comply with the guidelines set forth in this policy, Voiceflow will not initiate legal action against you under the Computer Fraud and Abuse Act (CFAA), the Digital Millennium Copyright Act (DMCA), or similar laws in other jurisdictions. We ask that you refrain from publicly disclosing any potential vulnerability until our security team has had the opportunity to review and address it.
