SECURITY AND COMPLIANCE

What we protect, and what we have not certified.

Your phone line carries the things customers will not put in an email: addresses, medical reasons for a visit, account disputes. This page describes how that data is separated and stored, in mechanisms rather than badges, and it ends with a plain list of the assurances we cannot give you yet.

One tenant cannot read another

Every row of data in Suvy Voice carries an organization id: agents, phone numbers, call logs, recordings, transcripts, connectors and billing. Separation is enforced in the database with row level security, not by remembering to add a filter in application code.

That matters most for partners. A reseller runs many client workspaces under one brand, and each of those workspaces is a separate organization that cannot see the others, even though they share a login screen and a domain.

IN PRACTICE
  • Row level security policies on every tenant-scoped table
  • Roles separated into platform admin, reseller and client
  • A reseller's clients are isolated from each other, not just from other resellers

Credentials stay on the server

When you connect Google Calendar, Outlook, Slack, Sheets or your CRM, the access token is stored server side and used server side. It is never sent to the browser and never embedded in the page, so it is not sitting in a JavaScript bundle a visitor could read.

The same rule applies to our own keys. Provider keys live in environment configuration, never in source control.

IN PRACTICE
  • Connector tokens held server side, scoped to one organization
  • No provider keys in client-side code
  • Disconnecting a connector revokes its use immediately

Recordings are not sitting on an open link

Call recordings and transcripts are served through authenticated endpoints tied to your workspace. They are not public object URLs that would work for anybody who happened to have the address, which is the usual way call audio leaks.

Recordings and transcripts are kept with your workspace and are exportable at any time. If your industry has a specific retention or deletion requirement, ask us what we can commit to in writing before you sign up rather than after.

IN PRACTICE
  • Authenticated access only, checked against your organization
  • Full transcript and audio available and exportable for every call
  • No public bucket URLs for call audio

The agent answers calls, it does not place them

Suvy Voice is inbound only. Your agent picks up the calls that come to your number and it never dials out, so there is no contact list to upload, no dialer to configure and no campaign to run.

That is worth saying on a compliance page because it removes a whole category of risk. The rules that govern automated outbound calling, consent records, Do Not Call scrubbing and calling hour limits, do not apply to a product that only ever answers.

IN PRACTICE
  • No outbound dialing, so no contact lists are uploaded to us
  • The agent says it is an assistant when a caller asks, and that cannot be switched off
  • Every call it handles was started by the caller, not by us

What it runs on

The voice engine runs on HIPAA-eligible infrastructure, with a compatible failover engine wired in so a degraded primary does not take your line down. That phrasing is deliberate and it is explained in the next section. The application, database, file storage, payments and email each run on infrastructure chosen for reliability and tenant separation, not stitched together after the fact.

We do not name every vendor on this page, because what matters to you is the guarantee, not the logo. If you need to know exactly whose infrastructure your call audio passes through before you sign up, ask us directly and we will tell you in writing.

IN PRACTICE
  • Voice engine on HIPAA-eligible infrastructure, with a compatible failover engine wired in
  • Application and database kept on separate, managed infrastructure
  • Payments and transactional email handled by processors chosen for reliability, not built in house
THE PART MOST SITES LEAVE OUT

Six things we cannot claim.

Vendor logos and inherited certifications get used as a substitute for a company’s own. If you are running a procurement review, these are the answers you would eventually get out of us anyway, so here they are first.

  • Suvysoft has not completed a SOC 2 audit of Suvy Voice. Our infrastructure providers hold their own certifications. Theirs are not ours, and we will not present them as ours.
  • We say built on HIPAA-eligible infrastructure, and we mean exactly that. Suvysoft has not been independently audited for HIPAA compliance and does not describe itself as HIPAA compliant. If your use needs a signed agreement covering protected health information, ask us before you sign up.
  • We do not publish an uptime percentage. We have not been running long enough to have measured one honestly, and a number nobody measured is worse than no number.
  • We have not commissioned an independent penetration test of Suvy Voice. When that changes, this line changes with it.
  • Nothing on this page is legal advice. You remain the party responsible for what your agent is configured to say and for any recording or notification obligations that apply where your callers are.
  • We have no customer count, no review score and no case study to show you. There is one voice agent our team built for a hospitality client on a different platform, and that is the whole of it.

If something here rules us out, better to know now.

Ask the awkward question before you sign up rather than after the first month. If we cannot do it, we will say so.