Amiovox.ai amiovox.ai
  • CX Consulting
  • VoxCare
  • VoxForce
  • Leadership
Talk to Us
  • CX Consulting
  • VoxCare
  • VoxForce
  • Leadership
  • Contact
Legal Center Security Policy

Security Policy

Draft prepared: September 2026  ·  Applies to: amiovox.ai, CX Consulting, VoxCare, and VoxForce

Draft

This page is a draft template, not a certified security attestation. It describes our intended practices in plain language. Have your security or compliance lead confirm it accurately reflects your actual controls — and pursue a formal audit (e.g., SOC 2, HITRUST) before relying on it for enterprise or healthcare procurement.

1. Overview

Amiovox.ai treats the security of client, patient, and partner data as core to how CX Consulting, VoxCare, and VoxForce operate — not an afterthought. This policy summarizes the practices we apply across our infrastructure, our team, and our vendors.

2. Infrastructure & Hosting

  • Our services run on Google Cloud Platform, using managed, enterprise-grade infrastructure (Cloud Run, Artifact Registry) rather than self-managed servers.
  • Data is encrypted in transit (TLS) and at rest, using our cloud provider's standard encryption.
  • Infrastructure changes are deployed through an automated pipeline from source control, so every change to production is tracked and attributable.

3. Access Controls

  • Access to production systems and client data is limited to team members and service accounts that need it to do their jobs.
  • We use identity federation and scoped service-account permissions rather than sharing long-lived credentials, wherever our tooling supports it.
  • Access is reviewed periodically and revoked promptly when someone's role changes or they leave.

4. Data Protection Practices

  • Data is used only for the purpose it was collected for — delivering CX Consulting, VoxCare, or VoxForce services — as described in our Privacy Policy.
  • Where we handle Protected Health Information on behalf of a VoxCare client, that handling is governed by a signed Business Associate Agreement in addition to this policy.
  • We minimize the data we retain and store to what's needed to deliver the service and meet legal or contractual retention requirements.

5. Vendor & Subprocessor Management

We rely on a small number of established infrastructure and communications vendors to operate our services. We review vendors for their own security practices before relying on them, and limit what data each vendor can access to what its function requires.

6. Incident Response

If we become aware of a security incident affecting client or patient data, we will investigate promptly, take steps to contain and remediate it, and notify affected clients (and, where required by a Business Associate Agreement or applicable law, affected individuals or regulators) without undue delay.

7. Responsible Disclosure

If you believe you've found a security vulnerability affecting Amiovox.ai, CX Consulting, VoxCare, or VoxForce, please report it to security@amiovox.ai rather than disclosing it publicly. We'll acknowledge your report and work with you to understand and address the issue.

8. Changes to This Policy

We may update this policy as our practices evolve. Material changes will be reflected by updating the "draft prepared" date at the top of this page.

9. Contact Us

Questions about this policy can be sent to security@amiovox.ai.

Amiovox.ai amiovox.ai

Conversational AI, put to work three ways.

  • CX Consulting
  • VoxCare
  • VoxForce
  • Contact
© 2026 Amiovox.ai ← Back to Legal Center
Legal Privacy Policy Security Policy Accessibility Site Map