Security at VXT
Built for privileged conversations.
How we protect your firm's data
Encrypted in transit and at rest
HTTPS and WSS for traffic, SRTP for voice and video, and encryption at rest by Google Cloud. Calls that cross the public telephone network carry the same limits as any PSTN call.
Your data stays yours
Recordings, transcripts and notes belong to your firm. Access, export or delete them at any time.
We do not train AI on your data
Summarisations are run through a zero data retention agreement. Nothing is kept by third-parties once the summary is returned.
Tested by third parties
We commission regular penetration testing. Our most recent was carried out by Carapace in 2025.
Built on Google Cloud
Built using Firestore, Cloud Storage and Firebase Authentication, with security in mind.
Where your data lives
Sydney
Ashburn, Virginia
Saint-Ghislain
Applies to recordings, greetings and sound clips. Call logs, notes, transcripts, summaries, voicemail and messages sit in our primary database in Sydney regardless of where your firm is based, and summarisation is processed by OpenAI in the United States. Our sub-processor list is published in full. If in-country storage of transcripts is a requirement for your firm, talk to us before you buy.
Security FAQs
We take a proactive approach with regular third-party penetration testing and provide multiple channels for reporting security issues, including a responsible disclosure form and published security contact. All incidents are raised in a dedicated internal channel and investigated with top priority, led by our Security Owner in coordination with relevant stakeholders.
In the case of a data breach, affected customers are notified as soon as possible after our investigation determines the scope of the breach, in compliance with all relevant jurisdictions – in New Zealand and Australia, this includes notifying the respective privacy authority "as soon as practicable."
Recordings, transcripts and summaries are retained indefinitely until you choose to delete them - you are in full control of your data retention. Deleting a call log permanently removes the associated recording, transcript and summary. When the last user in a team is deleted, all data associated with that team is also permanently deleted.
Your data is not used to train AI models. It is only used to deliver the services you have requested.
Google Cloud for hosting, Assembly AI for speech-to-text, OpenAI for summaries, Stripe for payments.
For a full list of third parties that may process data, see our sub-processors page.
MFA is available through federated identity providers. VXT supports sign-in with Google, Apple, and Microsoft, allowing your team to take advantage of the MFA and security policies already configured within those providers.
VXT provides role-based access control within organisations, configurable by org admins.
On the VXT side, ability to modify team settings is reserved to staff who are actively involved in support.
We follow strict internal security standards including full-disk encryption, two-factor authentication for online accounts, and least-privilege access.
VXT is hosted on Google Cloud Platform. Our primary database (including call logs, transcripts, summaries and metadata) is located in Sydney, Australia.
Call recordings and other files are stored in buckets specific to the region of the organisation: Australia/New Zealand data stays in AU, US/Canada in the US, and UK/Ireland/South Africa in Belgium (EU).
For a full list of third parties that may process data, see our sub-processors page.
Not yet. We are actively working towards SOC 2 and HIPAA compliance and the CIS Kubernetes Benchmark. Our infrastructure is hosted on Google Cloud Platform, which itself holds ISO 27001 and SOC 2 certifications.
We also commission regular third-party penetration testing - most recently conducted by Carapace in 2025.
Practice law, not paperwork
VXT works on the device you're using. It’s free to get started.
