§01Trust

Enterprise from day one.

Vorel runs real conversations for regulated industries. Security is not an enterprise upsell — it is the default.

SOC 2
Type II
HIPAA
Eligible
§02How we handle customer data
01

Access control

  • SSO via SAML, OIDC, and SCIM (Okta, Azure AD, Google).
  • Role-based scopes at tenant and flow level.
  • Short-TTL signed JWTs between orchestrator, agent, and tool layer.
  • Named-support MFA-required console for Enterprise.
02

Data handling

  • Tenant isolation with Postgres row-level security.
  • PCI and PHI redacted inline on voice and chat.
  • Zero data retention on model providers (Gemini, Anthropic).
  • Regional residency in US and EU; UAE, KSA, and UK on request.
03

Deployment options

  • Multi-tenant SaaS by default.
  • VPC deploy on AWS, GCP, and Azure for Enterprise.
  • On-prem bridge for restricted networks.
  • Bring-your-own carrier (Twilio, Telnyx) or provision through us.
04

Agent safety

  • Typed tool contracts. Every integration scoped and signed.
  • Staging replay of every tool call before it ships.
  • Hard spend caps per agent with automatic pause.
  • Full transcript audit with reviewer override.
§03Certifications and attestations
  • SOC 2 Type IIAnnual audit. Report on request under NDA.
  • HIPAA eligibleBAAs available on Operate and Enterprise.
  • GDPRStandard Contractual Clauses available. DPO named in the DPA.
  • ISO 27001In progress. Target Q4 2026.
  • PCI DSSScope-minimized. Payment data never persists in Vorel systems.
  • TX-RAMP / FedRAMPNot yet. On the roadmap for 2027.

Looking for the SIG, CAIQ, SOC 2 Type II report, or our data processing addendum? Write to [email protected]. We reply the same day.

Coordinating procurement?

We stand up a data room with your MSA, DPA, SOC 2 report, and answered SIG/CAIQ within an hour of the first call.