Skip to content

SONICVOX SECURITY OVERVIEW

Effective Date: June 1, 2026
Last Updated: July 5, 2026

Version: 1.0

This Security Overview is provided by WP Global Syndicate LLC, an Oklahoma limited liability company, doing business as SonicVox (“Company,” “we,” “us,” or “our”).

1. OVERVIEW

1.1 Purpose

This Security Overview describes the high-level information security practices of the Company that apply to the SonicVox platform, APIs, integrations, and hosted services.

1.2 Audience

This document is intended for prospective and current customers, partners, and regulators.

1.3 Non-Contractual Nature

This document is for informational purposes only and does not replace contractual security obligations set out in the Terms of Service, Data Processing Addendum (DPA), or any applicable customer agreement. This document does not create any legally binding obligations, representations, warranties, or guarantees regarding the security, availability, or performance of the Services.

1.4 Additional Information

Additional technical details, service commitments, or audit materials may be provided upon request or under contract.

2. SECURITY PRINCIPLES

2.1 Overview

The Company’s security program is guided by the following principles designed to protect the confidentiality, integrity, and availability of data:

2.2 Core Principles

2.2.1 Least Privilege

Access to systems and data is designed to be restricted to authorized personnel based on business need and regularly reviewed.

2.2.2 Defense in Depth

Multiple layers of security controls are implemented across infrastructure, applications, and data.

2.2.3 Data Minimization

Data collection and retention are limited to what is necessary for service delivery, contractual obligations, and legal compliance, including specific limitations applicable to biometric and voice-related data where required by law.

2.2.4 Privacy by Design

Security and privacy considerations are embedded into product development and system architecture.

2.2.5 Continuous Monitoring

Systems may be monitored, logged, and reviewed to help detect and respond to security events.

3. TECHNICAL SAFEGUARDS

3.1 Overview

The Company implements the following technical safeguards:

3.1.1 Encryption

Data is encrypted in transit and at rest using commercially reasonable encryption standards appropriate to the nature of the data and processing activities.

3.1.2 Authentication & Identity Management

Administrative and internal access uses commercially reasonable authentication mechanisms, including multi-factor authentication (MFA). Enterprise customers may be supported with SSO (SAML/OIDC) where applicable.

3.1.3 Access Control

Role-based access controls (RBAC) and least privilege principles are enforced. Access rights are periodically reviewed and logged.

3.1.4 Network Security

Infrastructure is hosted in commercially reasonable cloud environments using network segmentation, firewalls, and access controls to restrict unauthorized access.

3.1.5 Tenant Isolation

Logical separation mechanisms are used to support logical separation of customer data within a multi-tenant architecture.

3.1.6 Secure Development Practices

The Company follows secure development lifecycle practices, including code review, security testing, and controlled deployments.

3.1.7 Monitoring & Logging

System activity may be logged and monitored for security events, with alerts generated for suspicious activity where appropriate.

3.1.8 Backup & Recovery

Regular backups may be performed and tested to support data availability and recovery capabilities.

3.1.9 Data Deletion

Data is securely deleted in accordance with contractual requirements and applicable laws. The Company implements data retention and deletion practices designed to comply with applicable data protection and biometric data laws, including requirements related to the storage, use, and destruction of voice or audio-derived data where applicable.

Where required by applicable law or contract, the Company will delete or anonymize customer data, including voice-related data, within the timeframes required by applicable law or contract, following termination of services or fulfillment of the processing purpose, subject to legal retention obligations.

4. OPERATIONAL CONTROLS

4.1 Access Management

Access to systems and data is limited to authorized personnel based on role and business need, and is subject to periodic review.

4.2 Personnel Security

Personnel are subject to confidentiality obligations and receive appropriate security awareness training.

4.3 Incident Preparedness

Documented incident response procedures are maintained and periodically tested.

4.4 Control Maintenance

Security controls and practices are reviewed and updated on a regular basis.

5. INCIDENT RESPONSE

5.1 Incident Management

The Company maintains commercially reasonable procedures designed to:

    1. Help detect security incidents;
    2. Help contain and remediate threats;
    3. Notify affected customers where required by law.

5.2 Regulatory Notification

Where required by applicable law, the Company will notify relevant supervisory authorities within legally required timeframes of becoming aware of a personal data breach, unless otherwise permitted by law.

6. COMPLIANCE POSITION

6.1 Certification Status

The Company is not currently certified under SOC 2, ISO 27001, or similar frameworks.

6.2 Alignment Statement

Security practices are designed to align with generally accepted industry security principles.

7. THIRD-PARTY SERVICES & SUB-PROCESSORS

7.1 Use of Third Parties

The Company utilizes third-party service providers (including cloud infrastructure, analytics, and support tools) to operate the Services. The Company does not control and is not responsible for the independent security practices of third-party service providers.

7.2 Sub-Processor Disclosure

The Company shall maintain an up-to-date list of authorized Sub-processors, available to Customer at the SonicVox Sub-Processor List, published on the Company’s website and updated in accordance with Section 5.4 of the DPA. A copy may also be obtained upon written request to privacy@sonicvox.ai.

8. NON-CONTRACTUAL DISCLOSURE

8.1 Informational Purpose Only

This Security Overview is provided for informational purposes only and does not modify, supplement, or form part of any contractual agreement between the Company and its customers.

8.2 Governing Agreements

Security obligations, commitments, and remedies are governed exclusively by the applicable Terms of Service, DPA, and other binding agreements executed between the parties.

8.3 No Warranty

The Company does not warrant that the security controls described herein will prevent all security incidents or unauthorized access.

All security measures are provided on an “as is” and “as available” basis, subject to the limitations and disclaimers set forth in the applicable Terms of Service.

9. SECURITY CONTACT

9.1 Contact Information

For security-related inquiries or to report vulnerabilities, please contact:

WP Global Syndicate LLC dba SonicVox
Security Contact
security@sonicvox.ai

©2025 SONICVOX AI · All rights reserved.

Service Status