Free 5-Day Dispatcher Build

We build and run your AI dispatcher, and you keep the A$2,490 build fee.

Ends in
--d--h--m--s

AI voice agent security by deployment

What each deployment carries, from encryption and tenancy to sign-in and audit. Single-tenant deployments add their own network, keys and threat detection.

The call plane reads these stores through a grant on a key in your AWS account.

Controls by deployment

Control
ControlSharedDedicatedHybridYour account
TLS 1.2 or higher on every connection
Database encrypted under a customer-managed KMS key
Key held in your AWS accountOption
One call per single-use process
A separate IAM role per service
CloudTrail into a locked bucketYour trailYour trail
Own VPC, database and Bedrock quota
Private subnets and an egress allow-list
GuardDuty threat detectionYoursYours
Database failover in under 60 seconds
Single sign-on over SAML or OIDC
Telemetry kept in the account
No standing access to call data
Masking of card, TFN and Medicare numbers
Retention window with scheduled deletion
Append-only audit log of changes

Encryption keys

  • Database

    Aurora is encrypted at creation under a customer-managed KMS key, and every backup copy carries its own key in Melbourne.

  • Stored secrets

    API keys for your agent tools are KMS ciphertext in the row that owns them. The encryption context names the workspace, table and row, so a ciphertext cannot be moved to another row.

  • Key custody

    In Hybrid and Your account deployments the key lives in your AWS account, and in Dedicated it can, through a KMS grant. Revoking it makes the database, recordings and stored secrets unreadable.

Sign-in and access

  • Single sign-on

    Your team signs in through Entra ID, Okta or any identity provider that speaks SAML 2.0 or OIDC.

  • Roles

    Owners, admins and members, and members limited to the agents they work on.

  • Break-glass access

    Our engineers have no standing access to call data. They reach a deployment through a time-limited role logged in its CloudTrail, which you can disable in Hybrid and Your account deployments.

  • Service roles

    Each service has its own IAM role, limited to the actions and resources it needs. No long-lived AWS keys are stored anywhere.

Audit trail

  • CloudTrail

    Every AWS API call in our accounts is recorded by an organisation-wide trail into a bucket with Object Lock, in a separate account in Melbourne. In your account the trail is yours.

  • Platform audit log

    Billing, membership and configuration changes are written once to an append-only log, with the person who made each change.

Certifications

  • AWS infrastructure

    IRAP PROTECTEDSydney and Melbourne

    Assessed services the call plane runs on

    • ECS
    • Aurora
    • S3
    • KMS
    • SQS
    • Bedrock
    • Elastic Load Balancing

    This is AWS's assessment of its own services, and it does not cover our platform.

  • Our platform

    • PCI DSS SAQ-ASelf-assessed
    • Privacy Act 1988 (Cth) + 13 APPsSelf-attested
    • Notifiable Data Breaches schemeCompliant
    • GDPR (Art 28 processor)Self-attested
    • SOC 2 Type IIAudit pending
    • ISO/IEC 27001:2022Audit pending
    • Essential Eight (ASD)Mapped
    • HIPAA · IRAP · APRA CPS 234Out of scope
    Detail for each framework

Security questionnaires

We answer security questionnaires in writing and take your team through the architecture on a call. Send yours to hello@verticalai.com.au.