Encrypted everywhere
Every conversation, transcript, and insight is encrypted in transit with TLS 1.2+ and at rest with AES-256. Research assets live in private, access-controlled storage and are served only through short-lived signed URLs.
CrowdVox is trusted with candid human conversations. We protect that trust with enterprise-grade security at every layer, from the interview to the insight, and we can show your security team exactly how.
Every conversation, transcript, and insight is encrypted in transit with TLS 1.2+ and at rest with AES-256. Research assets live in private, access-controlled storage and are served only through short-lived signed URLs.
Single sign-on, multi-factor authentication with device binding, and role-based permissions scoped to your organization ensure only the right people see your research, and nothing more.
Every request, model invocation, and computation is logged with a traceable ID, and every published quote is machine-verified against its source transcript. We don't ask for trust; we produce evidence.
Security isn't a feature we added; it's how the platform is built. Every layer of CrowdVox assumes the layer above it could fail.
Technology is only half of security. Our operating practices cover the people, processes, and failure scenarios behind it.
A defined incident response process covers detection, containment, remediation, and recovery. Customers are notified of confirmed incidents affecting their data without undue delay, followed by a post-incident summary of root cause and corrective action.
Internal access to customer data is least-privilege and need-to-know. All personnel operate under confidentiality obligations, and access is reviewed regularly and revoked immediately on role change or departure.
Customer data is protected by automated, encrypted backups with defined retention. Recovery procedures are documented and exercised as part of our business continuity planning.
Customer data is hosted in enterprise cloud regions. Regional data residency options are available for enterprise engagements.
Our controls are built around recognized frameworks, so your security and legal teams can evaluate CrowdVox with confidence.
Data processing practices designed around GDPR and CCPA obligations. Data processing agreements, including subprocessor disclosures, are available to every customer.
Controls mapped to the SOC 2 Trust Services Criteria across security, availability, and confidentiality. Formal certification is on our active roadmap; our current control mapping is available under NDA.
We welcome reports from security researchers and commit to timely triage, remediation, and acknowledgment of verified findings. Contact security@crowdvox.ai.
Your data belongs to you. CrowdVox never sells customer or participant data, and your research is never used to train models for other customers. See our Privacy Controls for how we protect the people behind the conversations.
Security is a program, not a page. Here is what we are actively investing in next, stated plainly, because your diligence deserves candor.
On a recurring cadence, with summaries available to customers under NDA.
Building on our existing control mapping.
With automated credential rotation.
Layered on top of our existing identity-minimizing design.
Integrated into the delivery pipeline.
We're happy to walk your security, legal, and procurement teams through our architecture, controls, and documentation. We support security questionnaires and RFP responses as part of enterprise procurement.