SONICVOX SECURITY OVERVIEW
Effective Date: June 1, 2026
Last Updated: July 5, 2026
Version: 1.0
This Security Overview is provided by WP Global Syndicate LLC, an Oklahoma limited liability company, doing business as SonicVox (“Company,” “we,” “us,” or “our”).
1. OVERVIEW
1.1 Purpose
This Security Overview describes the high-level information security practices of the Company that apply to the SonicVox platform, APIs, integrations, and hosted services.
1.2 Audience
This document is intended for prospective and current customers, partners, and regulators.
1.3 Non-Contractual Nature
This document is for informational purposes only and does not replace contractual security obligations set out in the Terms of Service, Data Processing Addendum (DPA), or any applicable customer agreement. This document does not create any legally binding obligations, representations, warranties, or guarantees regarding the security, availability, or performance of the Services.
1.4 Additional Information
Additional technical details, service commitments, or audit materials may be provided upon request or under contract.
2. SECURITY PRINCIPLES
2.1 Overview
The Company’s security program is guided by the following principles designed to protect the confidentiality, integrity, and availability of data:
2.2 Core Principles
2.2.1 Least Privilege
Access to systems and data is designed to be restricted to authorized personnel based on business need and regularly reviewed.
2.2.2 Defense in Depth
Multiple layers of security controls are implemented across infrastructure, applications, and data.
2.2.3 Data Minimization
Data collection and retention are limited to what is necessary for service delivery, contractual obligations, and legal compliance, including specific limitations applicable to biometric and voice-related data where required by law.
2.2.4 Privacy by Design
Security and privacy considerations are embedded into product development and system architecture.
2.2.5 Continuous Monitoring
Systems may be monitored, logged, and reviewed to help detect and respond to security events.
3. TECHNICAL SAFEGUARDS
3.1 Overview
The Company implements the following technical safeguards:
3.1.1 Encryption
Data is encrypted in transit and at rest using commercially reasonable encryption standards appropriate to the nature of the data and processing activities.
3.1.2 Authentication & Identity Management
Administrative and internal access uses commercially reasonable authentication mechanisms, including multi-factor authentication (MFA). Enterprise customers may be supported with SSO (SAML/OIDC) where applicable.
3.1.3 Access Control
Role-based access controls (RBAC) and least privilege principles are enforced. Access rights are periodically reviewed and logged.
3.1.4 Network Security
Infrastructure is hosted in commercially reasonable cloud environments using network segmentation, firewalls, and access controls to restrict unauthorized access.
3.1.5 Tenant Isolation
Logical separation mechanisms are used to support logical separation of customer data within a multi-tenant architecture.
3.1.6 Secure Development Practices
The Company follows secure development lifecycle practices, including code review, security testing, and controlled deployments.
3.1.7 Monitoring & Logging
System activity may be logged and monitored for security events, with alerts generated for suspicious activity where appropriate.
3.1.8 Backup & Recovery
Regular backups may be performed and tested to support data availability and recovery capabilities.
3.1.9 Data Deletion
Data is securely deleted in accordance with contractual requirements and applicable laws. The Company implements data retention and deletion practices designed to comply with applicable data protection and biometric data laws, including requirements related to the storage, use, and destruction of voice or audio-derived data where applicable.
Where required by applicable law or contract, the Company will delete or anonymize customer data, including voice-related data, within the timeframes required by applicable law or contract, following termination of services or fulfillment of the processing purpose, subject to legal retention obligations.
4. OPERATIONAL CONTROLS
4.1 Access Management
Access to systems and data is limited to authorized personnel based on role and business need, and is subject to periodic review.
4.2 Personnel Security
Personnel are subject to confidentiality obligations and receive appropriate security awareness training.
4.3 Incident Preparedness
Documented incident response procedures are maintained and periodically tested.
4.4 Control Maintenance
Security controls and practices are reviewed and updated on a regular basis.
5. INCIDENT RESPONSE
5.1 Incident Management
The Company maintains commercially reasonable procedures designed to:
- Help detect security incidents;
- Help contain and remediate threats;
- Notify affected customers where required by law.
5.2 Regulatory Notification
Where required by applicable law, the Company will notify relevant supervisory authorities within legally required timeframes of becoming aware of a personal data breach, unless otherwise permitted by law.
6. COMPLIANCE POSITION
6.1 Certification Status
The Company is not currently certified under SOC 2, ISO 27001, or similar frameworks.
6.2 Alignment Statement
Security practices are designed to align with generally accepted industry security principles.
7. THIRD-PARTY SERVICES & SUB-PROCESSORS
7.1 Use of Third Parties
The Company utilizes third-party service providers (including cloud infrastructure, analytics, and support tools) to operate the Services. The Company does not control and is not responsible for the independent security practices of third-party service providers.
7.2 Sub-Processor Disclosure
The Company shall maintain an up-to-date list of authorized Sub-processors, available to Customer at the SonicVox Sub-Processor List, published on the Company’s website and updated in accordance with Section 5.4 of the DPA. A copy may also be obtained upon written request to privacy@sonicvox.ai.
8. NON-CONTRACTUAL DISCLOSURE
8.1 Informational Purpose Only
This Security Overview is provided for informational purposes only and does not modify, supplement, or form part of any contractual agreement between the Company and its customers.
8.2 Governing Agreements
Security obligations, commitments, and remedies are governed exclusively by the applicable Terms of Service, DPA, and other binding agreements executed between the parties.
8.3 No Warranty
The Company does not warrant that the security controls described herein will prevent all security incidents or unauthorized access.
All security measures are provided on an “as is” and “as available” basis, subject to the limitations and disclaimers set forth in the applicable Terms of Service.
9. SECURITY CONTACT
9.1 Contact Information
For security-related inquiries or to report vulnerabilities, please contact:
WP Global Syndicate LLC dba SonicVox
Security Contact
security@sonicvox.ai
