Security & compliance,
documented and verified.
Vocant is built for teams that handle sensitive audio. Here's exactly how we protect your data — the attestations we hold, the controls we run, and the documents you can request for your vendor review.
How Vocant thinks
about your data.
Vocant is a privacy-first AI transcription platform. We process audio and video for one purpose — to return the transcript and enrichment you asked for — and then we get out of the way. Source files are processed in-memory and purged on your schedule. Your content is never used to train generalized models. Encryption is applied end to end.
This page is our public summary. Enterprise and regulated buyers can request our full SOC 2 report, security documentation, and a completed vendor questionnaire under NDA — see Documents below.
Standards enterprise teams
actually check.
Independent attestation and framework alignment that support security reviews in regulated industries.
Your data lifecycle,
under your control.
Where Vocant
runs and rests.
Vocant's services are hosted in the United States. Transcription runs on self-hosted inference servers; storage and application layers use vetted, contractually-bound providers.
The vendors
in our pipeline.
Vocant uses a small set of vetted subprocessors, each bound by their own terms and, where applicable, contractual commitments to Vocant. Enterprise agreements may add customer-specific subprocessors identified in contract documents.
| Subprocessor | Purpose | Data handled |
|---|---|---|
| Cloudflare | Hosting & network security | Request metadata, edge traffic |
| Supabase | Database & authentication | Account data, transcripts, metadata |
| Vercel | Web application hosting | Application traffic |
| Stripe | Payment processing | Billing details (no card data stored by Vocant) |
A current subprocessor list is maintained and available to customers. Material changes are communicated per our agreements. Questions? security@vocant.ai
Secure by
development practice.
Privacy is the
default, not the upsell.
Every plan — including Free — gets configurable retention, encryption, and our no-training commitment. We don't sell or rent personal information. Our full Privacy Policy details what we collect, how we use it, and the rights available to you.
When something
goes wrong.
Vocant maintains documented incident response procedures covering detection, containment, and notification. In the event of a security incident affecting your data, we follow the notification commitments in your agreement and applicable law. We're happy to walk enterprise customers through our incident response process during a security review.
To report a security concern or suspected incident, contact security@vocant.ai.
For your
vendor review.
Public documents are linked directly. Sensitive documents — our SOC 2 report and detailed security materials — are available to enterprise buyers and customers under NDA. Request access and we'll get back to you quickly.
Ready to review Vocant?
We'll make it easy.
Get our SOC 2 report, security documentation, and a completed questionnaire — or talk directly with our security team.