Security at VXT

Built for privileged conversations.

How we protect your firm's data

Encrypted in transit and at rest

HTTPS and WSS for traffic, SRTP for voice and video, and encryption at rest by Google Cloud. Calls that cross the public telephone network carry the same limits as any PSTN call.

Your data stays yours

Recordings, transcripts and notes belong to your firm. Access, export or delete them at any time.

We do not train AI on your data

Summarisations are run through a zero data retention agreement. Nothing is kept by third-parties once the summary is returned.

Tested by third parties

We commission regular penetration testing. Our most recent was carried out by Carapace in 2025.

Built on Google Cloud

Built using Firestore, Cloud Storage and Firebase Authentication, with security in mind.

99.99%
Uptime across the VXT platform
Zero
Data breaches to date
2025
Latest independent penetration test

Where your data lives

Australia or New Zealand

Sydney

United States or Canada

Ashburn, Virginia

United Kingdom, Ireland or South Africa

Saint-Ghislain

Applies to recordings, greetings and sound clips. Call logs, notes, transcripts, summaries, voicemail and messages sit in our primary database in Sydney regardless of where your firm is based, and summarisation is processed by OpenAI in the United States. Our sub-processor list is published in full. If in-country storage of transcripts is a requirement for your firm, talk to us before you buy.

Security FAQs

How do you approach and respond to security incidents?

We take a proactive approach with regular third-party penetration testing and provide multiple channels for reporting security issues, including a responsible disclosure form and published security contact. All incidents are raised in a dedicated internal channel and investigated with top priority, led by our Security Owner in coordination with relevant stakeholders.

In the case of a data breach, affected customers are notified as soon as possible after our investigation determines the scope of the breach, in compliance with all relevant jurisdictions – in New Zealand and Australia, this includes notifying the respective privacy authority "as soon as practicable."

How long is data retained, and can it be permanently deleted?

Recordings, transcripts and summaries are retained indefinitely until you choose to delete them - you are in full control of your data retention. Deleting a call log permanently removes the associated recording, transcript and summary. When the last user in a team is deleted, all data associated with that team is also permanently deleted.

Is customer data used to train AI models?

Your data is not used to train AI models. It is only used to deliver the services you have requested.

Which third parties process our data?

Google Cloud for hosting, Assembly AI for speech-to-text, OpenAI for summaries, Stripe for payments.

For a full list of third parties that may process data, see our sub-processors page.

Do you support multi-factor authentication (MFA)?

MFA is available through federated identity providers. VXT supports sign-in with Google, Apple, and Microsoft, allowing your team to take advantage of the MFA and security policies already configured within those providers.

What access controls are in place?

VXT provides role-based access control within organisations, configurable by org admins.

On the VXT side, ability to modify team settings is reserved to staff who are actively involved in support.

We follow strict internal security standards including full-disk encryption, two-factor authentication for online accounts, and least-privilege access.

Where is client data stored?

VXT is hosted on Google Cloud Platform. Our primary database (including call logs, transcripts, summaries and metadata) is located in Sydney, Australia.

Call recordings and other files are stored in buckets specific to the region of the organisation: Australia/New Zealand data stays in AU, US/Canada in the US, and UK/Ireland/South Africa in Belgium (EU).

For a full list of third parties that may process data, see our sub-processors page.

Do you hold any certifications such as ISO 27001 or SOC 2?

Not yet. We are actively working towards SOC 2 and HIPAA compliance and the CIS Kubernetes Benchmark. Our infrastructure is hosted on Google Cloud Platform, which itself holds ISO 27001 and SOC 2 certifications.

We also commission regular third-party penetration testing - most recently conducted by Carapace in 2025.

Practice law, not paperwork

VXT works on the device you're using. It’s free to get started.