§01Trust
Enterprise from day one.
Vorel runs real conversations for regulated industries. Security is not an enterprise upsell — it is the default.
- SOC 2
- Type II
- HIPAA
- Eligible
§02How we handle customer data
01
Access control
- SSO via SAML, OIDC, and SCIM (Okta, Azure AD, Google).
- Role-based scopes at tenant and flow level.
- Short-TTL signed JWTs between orchestrator, agent, and tool layer.
- Named-support MFA-required console for Enterprise.
02
Data handling
- Tenant isolation with Postgres row-level security.
- PCI and PHI redacted inline on voice and chat.
- Zero data retention on model providers (Gemini, Anthropic).
- Regional residency in US and EU; UAE, KSA, and UK on request.
03
Deployment options
- Multi-tenant SaaS by default.
- VPC deploy on AWS, GCP, and Azure for Enterprise.
- On-prem bridge for restricted networks.
- Bring-your-own carrier (Twilio, Telnyx) or provision through us.
04
Agent safety
- Typed tool contracts. Every integration scoped and signed.
- Staging replay of every tool call before it ships.
- Hard spend caps per agent with automatic pause.
- Full transcript audit with reviewer override.
§03Certifications and attestations
- SOC 2 Type IIAnnual audit. Report on request under NDA.
- HIPAA eligibleBAAs available on Operate and Enterprise.
- GDPRStandard Contractual Clauses available. DPO named in the DPA.
- ISO 27001In progress. Target Q4 2026.
- PCI DSSScope-minimized. Payment data never persists in Vorel systems.
- TX-RAMP / FedRAMPNot yet. On the roadmap for 2027.
Looking for the SIG, CAIQ, SOC 2 Type II report, or our data processing addendum? Write to [email protected]. We reply the same day.
Coordinating procurement?
We stand up a data room with your MSA, DPA, SOC 2 report, and answered SIG/CAIQ within an hour of the first call.