Free 5-Day Dispatcher Build

We build and run your AI dispatcher, and you keep the A$2,490 build fee.

Ends in
--d--h--m--s

AI voice agent security questionnaire answers

The questions a security review asks about a voice agent deployment, answered in writing. Each answer links to the page with the detail.

Hosting and residency

6 questions

The platform runs on AWS in ap-southeast-2, Sydney. Failover answering, backups and the audit trail sit in ap-southeast-4, Melbourne.

Architecture

Yes. In a Hybrid deployment the call plane runs in your account and we run the control plane. In a Your account deployment both planes run there, and the dashboard is reachable only inside your network.

Deployments

No. The platform runs on AWS in Sydney. The closest option is a Your account deployment, where both planes run in an AWS account you own and the dashboard is reachable only inside your network.

Dedicated, Hybrid and Your account deployments are single-tenant, each with its own AWS account, VPC, database, keys and Bedrock quota. The shared platform separates customers by workspace with row-level security.

Call audio, recordings, transcripts and model calls are processed and stored in Australia. Telnyx's call control API in the United States carries caller numbers and call IDs, and Deepgram keeps billing metadata there.

Data

Claude on Amazon Bedrock answers them, through Bedrock's Australian profile, which keeps inference in Sydney and Melbourne. No call fails over to a model outside Australia.

Data protection

5 questions

No. Amazon Bedrock does not use your prompts or replies to train base models and does not share them with model providers. Bedrock invocation logging is off.

Transcripts and call records follow the retention window you set, and a daily job deletes what is past it. Recordings are kept for 30 days unless an agent is set to keep them longer.

Card numbers, Tax File Numbers, Medicare numbers and US Social Security numbers are masked in every transcript line before it is saved.

Yes. In Hybrid and Your account deployments the data is in your own AWS account. In every deployment we export or delete a workspace's data on request.

Point-in-time recovery covers 7 days in Sydney. A daily copy goes to a separate account in Melbourne under its own key, and 7 copies are kept.

Operations

Encryption and keys

4 questions

Every connection uses TLS 1.2 or higher, including the audio stream from the carrier and the connections to Deepgram and Bedrock. The public phone network itself is unencrypted, as it is for any phone call.

The database, recordings and files are encrypted under a customer-managed KMS key. Stored secrets are KMS ciphertext in the row that owns them.

Yes. In Hybrid and Your account deployments the KMS key is in your AWS account, and in Dedicated it can be, through a KMS grant. Revoking it makes the database, recordings and stored secrets unreadable.

Security

Each key is KMS ciphertext in the row that owns it, with an encryption context naming the workspace, table and row. The call worker's supervisor decrypts it in memory for the call.

Identity and access

4 questions

Yes. Your team signs in through any SAML 2.0 or OIDC identity provider, such as Entra ID or Okta.

No engineer has standing access to call data. Access to a deployment goes through a time-limited break-glass role, every session is logged in the account's CloudTrail, and in Hybrid and Your account deployments you can disable the role.

Owner, admin and member, plus members limited to the agents they work on.

Each service has its own IAM task role, limited to the actions and resources it needs. No long-lived AWS keys are stored in the platform.

Logging and monitoring

4 questions

Logs, metrics and traces stay in CloudWatch in the call plane account for 14 days. CloudTrail records AWS API calls, and the platform's append-only audit log records configuration changes.

In Hybrid and Your account deployments CloudTrail writes to your own trail. In every deployment the platform's audit log shows who changed what and when.

Dedicated deployments run GuardDuty. In Hybrid and Your account deployments your own threat detection covers the account.

A canary call tests the line every 10 minutes in business hours and every 30 minutes overnight. Two failures in a row page the on-call engineer from Melbourne.

Resilience and recovery

5 questions

Calls in progress end. New calls ring for about 5 seconds, then a handler in Melbourne answers and forwards the caller to your fallback number, and the database restores in Melbourne from the daily copy.

A caller hears no change. New calls move to the new version only after it passes with 0 dropped calls, and calls in progress finish where they started.

The recovery point on loss of the Sydney region is 24 hours, from the daily copy in Melbourne. The recovery time is set in your contract.

Single-tenant deployments run a database reader, which takes over in under 60 seconds. Calls in progress continue, and new calls load the last good copy of each agent from S3.

Availability terms are set in the contract for each enterprise deployment.

Vendors

4 questions

Amazon Web Services hosts the platform and runs the models. Telnyx carries the calls and Deepgram runs speech in Sydney. ElevenLabs, Cartesia or Fish Audio process text only if an agent uses one of their voices.

Sub-processors

Yes, with Deepgram's self-hosted speech on a Deepgram Enterprise licence. It runs on GPU instances in the call plane, and only usage metadata such as call duration leaves for licensing.

Yes. Your PBX or session border controller connects to a Telnyx SIP connection, calls reach the agent, and transfers go back over SIP.

Network

Enterprise deployments do not use it. The direct Anthropic API offers no Australian region, so every model call runs on Bedrock in Australia.

Compliance

4 questions

No. The SOC 2 Type II and ISO/IEC 27001 audits are pending, and the security page lists the status of every framework.

Framework statuses

No. AWS assesses the services the call plane runs on at IRAP PROTECTED in Sydney and Melbourne, including ECS, Aurora, S3, KMS, SQS and Bedrock. That assessment covers AWS's services, not our platform.

Yes. Our standard DPA is published, and an enterprise deployment's sub-processors are set in its contract.

DPA

We follow the Notifiable Data Breaches scheme. We assess a suspected breach within 30 days and notify the OAIC and affected individuals as soon as practicable once we have reasonable grounds to believe an eligible breach has occurred.

Security questionnaires

We answer security questionnaires in writing and take your team through the architecture on a call. Send yours to hello@verticalai.com.au.