Overview Compliance Data Security Infrastructure Subprocessors Application Security Privacy Incident Response Documents
Trust Center

Security & compliance,
documented and verified.

Vocant is built for teams that handle sensitive audio. Here's exactly how we protect your data — the attestations we hold, the controls we run, and the documents you can request for your vendor review.

AICPA SOC 2 attestation seal
Overview

How Vocant thinks
about your data.

Vocant is a privacy-first AI transcription platform. We process audio and video for one purpose — to return the transcript and enrichment you asked for — and then we get out of the way. Source files are processed in-memory and purged on your schedule. Your content is never used to train generalized models. Encryption is applied end to end.

This page is our public summary. Enterprise and regulated buyers can request our full SOC 2 report, security documentation, and a completed vendor questionnaire under NDA — see Documents below.

Compliance & Attestations

Standards enterprise teams
actually check.

Independent attestation and framework alignment that support security reviews in regulated industries.

AICPA SOC 2 seal
SOC 2 Type I
Attested
Security & Privacy Trust Services Criteria. Examined by CertPro, as of July 23, 2026. Full report available under NDA.
🔒
HIPAA
BAA Available
Business Associate Agreements offered on Pro and Enterprise plans to support ePHI workflows in healthcare.
🌐
GDPR
Compatible
EU-compatible data handling practices, data processing terms, and configurable retention to support data subject rights.
🛡️
Encryption
Enforced
AES-256 at rest and TLS 1.2+ in transit across the entire processing and storage pipeline.
Data Security

Your data lifecycle,
under your control.

Encryption in transit & at rest
TLS 1.2+ protects data moving to and from Vocant. AES-256 protects data stored on our infrastructure. Keys are managed and rotated according to documented procedures.
In-memory processing
Audio and video are transcribed in-memory on Vocant's self-hosted servers. The source file is purged from the processing environment the moment transcription completes.
Configurable retention (0–30 days)
You set how long source files are retained — from zero (purged immediately) to 30 days. Transcripts remain in your account until you delete them or close the account.
No raw audio in backups
Raw customer audio is never written to system backups. Once a source file is purged per your retention setting, no residual copy remains anywhere in our infrastructure.
No model training on your data
Vocant does not use customer audio, video, or transcripts to train generalized AI or ML models unless you expressly agree in writing. Enterprise fine-tuning is opt-in and isolated to your organization.
Restricted access
Staff access to customer content is restricted by default and subject to documented escalation procedures. Access is logged and reviewed as part of our control set.
Infrastructure

Where Vocant
runs and rests.

Vocant's services are hosted in the United States. Transcription runs on self-hosted inference servers; storage and application layers use vetted, contractually-bound providers.

Self-hosted inference
Transcription and NLP enrichment run on Vocant-operated servers, not shipped to third-party AI APIs — a key control for keeping sensitive audio inside our boundary.
US-based hosting
Data is processed and stored in the United States unless a customer agreement specifies otherwise. International customers are notified of US data transfer.
Business continuity
Documented backup and recovery procedures for the application and storage layers. Raw customer audio is deliberately excluded from backups by design.
Network security
Edge protection and network security are provided through Cloudflare, including DDoS mitigation and TLS termination in front of application services.
Subprocessors

The vendors
in our pipeline.

Vocant uses a small set of vetted subprocessors, each bound by their own terms and, where applicable, contractual commitments to Vocant. Enterprise agreements may add customer-specific subprocessors identified in contract documents.

SubprocessorPurposeData handled
CloudflareHosting & network securityRequest metadata, edge traffic
SupabaseDatabase & authenticationAccount data, transcripts, metadata
VercelWeb application hostingApplication traffic
StripePayment processingBilling details (no card data stored by Vocant)

A current subprocessor list is maintained and available to customers. Material changes are communicated per our agreements. Questions? security@vocant.ai

Application Security

Secure by
development practice.

Secure SDLC
Development follows a documented Software Development Lifecycle policy, including code review and change management controls maintained under our SOC 2 program.
Vulnerability management
Dependencies and infrastructure are monitored for known vulnerabilities, with patching prioritized by severity as part of ongoing operations.
Access control
Least-privilege access to production systems, with authentication controls and access reviews. Enterprise SSO/SAML is available for customer accounts.
Responsible disclosure
We welcome security researchers. Report a suspected vulnerability to security@vocant.ai and we'll respond promptly.
Privacy

Privacy is the
default, not the upsell.

Every plan — including Free — gets configurable retention, encryption, and our no-training commitment. We don't sell or rent personal information. Our full Privacy Policy details what we collect, how we use it, and the rights available to you.

Privacy Policy
How we collect, use, and protect information
View
Terms & Conditions
The agreement governing use of Vocant
View
Data Processing Terms
DPA available for customers with GDPR obligations
Request
Incident Response

When something
goes wrong.

Vocant maintains documented incident response procedures covering detection, containment, and notification. In the event of a security incident affecting your data, we follow the notification commitments in your agreement and applicable law. We're happy to walk enterprise customers through our incident response process during a security review.

To report a security concern or suspected incident, contact security@vocant.ai.

Documents

For your
vendor review.

Public documents are linked directly. Sensitive documents — our SOC 2 report and detailed security materials — are available to enterprise buyers and customers under NDA. Request access and we'll get back to you quickly.

SOC 2 Type I Report
Security & Privacy criteria · examined by CertPro
Request · NDA
Security Overview / Whitepaper
Architecture and controls summary for security teams
Request
Vendor Security Questionnaire
We'll complete your questionnaire (CAIQ, SIG, or custom)
Request
HIPAA Business Associate Agreement
Available on Pro and Enterprise plans
Request

Ready to review Vocant?
We'll make it easy.

Get our SOC 2 report, security documentation, and a completed questionnaire — or talk directly with our security team.