Every claim we make, with the evidence behind it.
This page is read from the trust register rather than written about it. A claim whose verification has lapsed appears as qualified, whatever its stored status says — and four of the things a security reviewer will ask for are not ours to assert at all. Those are listed too.
How to read this
Two words carry the weight. Evidenced means we measured it, recorded what proves it, and the verification is current. Qualified means one of those three is missing — the control may well be in place, and we are not going to present it as proven while a review date has passed or an independent party has not looked.
Nothing on this page is a certification. VoiceInsights holds no SOC 2 report, no ISO/IEC 27001 certificate, no independent penetration test and no independently audited accessibility conformance. Each is listed below as requiring an independent party, because a buyer discovering that during implementation rather than during procurement is how a project loses six weeks.
The register
Grouped by domain, each with the evidence recorded against it and the state of its verification.
Where data is processed
Per component and provider, with the verification state attached to each. This is the question institutional buyers ask first and the one most often answered too confidently.
Stated precisely
- Jurisdiction controls are available in the underlying infrastructure and are not currently configured. The platform cannot read the resulting placement.
- We will not tell you data “stays in” a named country, because we cannot verify it. Where residency is a contractual requirement, it is a scoping conversation rather than a checkbox.
Who else touches customer data
The full subprocessor register, with the state of each data processing agreement.
Evidence a reviewer can ask for
What the procurement register holds, including the reports that do not exist. An absent report is listed rather than omitted — omission is what a due-diligence team finds later and holds against you.
The rest of the assurance estate
Each of these answers a question the register above does not, in the detail a reviewer needs.
Security
Identity, access, tenant isolation, session handling and monitoring.
Data protection
Ownership, controller and processor roles, consent, retention, deletion and legal hold.
Responsible AI
Where a model may contribute, where it may not, and what must be true before AI-assisted output publishes.
Subprocessors
Who processes customer data, for what, and the state of each agreement.
Accessibility
The conformance target, what was measured, how, and what has not been independently audited.
Compliance
Status across data protection, research ethics, safeguarding, governance and continuity.
Safeguarding
Consent, access restriction, escalation and referral in the approved collection context.
Service levels and continuity
Availability posture, backup and recovery, and what has and has not been rehearsed.
Platform status
Live component health and incident history, separate from any sales conversation.