# Security · Vaakyo

> How Vaakyo protects your calls and data: where it is stored, encryption, roles, audit logs, the DPDP Act, TRAI calling hours and responsible calling.

Source: https://vaakyo.com/security

Security

# Your customers' conversations, **protected**

Calls carry names, numbers and sometimes payment details. Here is how we keep them safe.

-   TLS everywhere
-   Encrypted storage
-   Two-step sign-in
-   Role-based access
-   Audit log
-   Signed webhooks

## Encryption

-   Every connection to the console, the API and our speech and telephony providers uses TLS.
-   Recordings, uploads and backups are stored in encrypted cloud storage.
-   Provider keys and two-step verification secrets are encrypted before they are stored; recovery codes and API keys are stored hashed.

## Access control

-   Each workspace's data is separate: every request is checked against the workspace it belongs to.
-   Roles (owner, admin, developer and viewer) decide who can see calls, edit agents or manage billing.
-   Two-step verification with an authenticator app, and sign-in sessions you can end from the console.

## API and integrations

-   API keys carry only the permissions you give them, and can be revoked at any time.
-   Webhooks are signed (HMAC-SHA256 with a timestamp), so your server can check they came from us.
-   AI apps connect over the MCP server with OAuth 2.1 and PKCE, with permissions capped and re-checked on every request.
-   Tools an agent calls must be on the public internet: private and internal addresses are refused.

## Accountability

-   Every change by a person or a key (agents, numbers, members, billing) is written to an audit log your admins can read.
-   Every workspace is verified (KYC) before it can call customers.
-   Our own team signs in with two-step verification, and support access is read-only.

## Responsible calling

-   Queued outbound calls wait for the agent's calling hours, and each campaign has its own calling window.
-   Every call is checked afterwards against platform rules, including TRAI's 9:00 to 21:00 IST window for promotional calls. Repeated violations freeze the agent until our team has reviewed it.
-   Agents can be told to identify themselves as AI and to end the call when asked.
-   Our Acceptable Use Policy forbids spam, calls to DND numbers without consent and impersonation.

## Where your data is

-   Call recordings, uploaded files and the nightly database backups are kept in Azure Blob Storage, encrypted at rest.
-   Transcripts and call data are kept in Vaakyo's database, separated by workspace.
-   During a call, the audio and text go to the speech and language models you chose for that agent, and nowhere else.
-   Recording can be switched off for any agent.

## Indian data protection law

-   Our privacy policy is written to meet the Digital Personal Data Protection Act, 2023 and the IT Act, 2000.
-   For the people your agents speak with, you are the data fiduciary and Vaakyo is your data processor: we use their data only to run your calls.
-   Some speech and language providers process data outside India. We transfer data only to countries the Government of India has not restricted under the DPDP Act.
-   A named grievance officer answers privacy complaints, as the Act requires.

## Reliability

-   Nightly encrypted backups of the database, kept for a rolling window.
-   Zero-downtime deploys: live calls finish on the old version while new calls start on the new one.
-   Speech providers have automatic fallbacks, so one vendor's outage doesn't drop your calls.

## Found a security **issue?**

Please email [hello@vaakyo.com](mailto:hello@vaakyo.com?subject=Security%20report) with the details and steps to reproduce. We'll reply quickly and won't take action against good-faith research.

---

More for agents: https://vaakyo.com/llms.txt · Docs: https://docs.vaakyo.com · Sitemap: https://vaakyo.com/sitemap-index.xml
