Security & Trust

How we protect your account, your data, and the people you call.

Infrastructure

Veyce is hosted on Vercel (application and static delivery) and Supabase (database, authentication, and real-time). Both platforms maintain enterprise-grade infrastructure security, redundancy, and availability. We do not run or manage our own servers.

Supabase uses PostgreSQL on AWS infrastructure in the United States. Vercel serves the application via a global edge network with automatic TLS certificate management.

Security Practices

Encryption in transit

All data transmitted between your browser and Veyce is encrypted using TLS 1.2 or higher. HTTP requests are automatically redirected to HTTPS.

Encryption at rest

API keys and credentials you store in Veyce (Twilio, OpenAI, etc.) are encrypted at rest using AES-256 before being written to the database.

Row-level security

Supabase RLS policies enforce data isolation at the database level. Every query is automatically scoped to your organization — no query can return another user's data.

Authentication

Passwords are hashed using bcrypt and never stored in plaintext. Sessions use signed, HTTP-only cookies validated on every request and cannot be read or modified by client-side scripts.

No credential logging

API keys and tokens you store in Veyce are never written to application logs, error trackers, or any system where they could be exposed in plaintext.

Error monitoring

We use Sentry for error monitoring and diagnostics. Sentry is configured to scrub sensitive data from error reports before transmission.

Call Data and Recordings

Call recordings are stored directly in your connected Twilio account, not in Veyce's infrastructure. Veyce stores only call metadata (duration, outcome, disposition, notes) — not audio files.

You retain full control over your call recordings through your Twilio account dashboard, including the ability to delete recordings at any time. Veyce does not have access to your Twilio account beyond the permissions granted by your API credentials.

Third-Party Services

Veyce relies on the following third-party providers to deliver the Service. Each maintains its own security program:

ProviderRoleData handled
SupabaseDatabase & authAll account and lead data
VercelApp hosting & deliveryRequest logs, no persistent data
StripePayment processingBilling and subscription data
SentryError monitoringScrubbed error/diagnostic data
TwilioVoice (your account)Your call recordings (not ours)

Access Controls

Veyce enforces organization-level data isolation. Team members can only access data within their own organization. Administrators can manage team member roles and permissions from the Organization page.

Veyce employees do not have routine access to customer data. Access to production infrastructure is restricted to authorized personnel and is logged.

Certifications

Veyce does not currently hold SOC 2, ISO 27001, or other formal security certifications. We implement industry-standard security practices as described on this page and rely on certified infrastructure providers (Supabase on AWS, Vercel) for underlying platform security.

If your organization requires formal certification documentation, contact us to discuss your requirements.

Security Incidents

If we become aware of a security incident affecting your data, we will notify you at the email address on your account without undue delay as required by applicable law, and provide information about the nature of the incident, data affected, and steps we have taken or are taking in response.

To report a security vulnerability, email info@veyce.com.au. We will acknowledge all security reports within 3 business days. We ask that you practice responsible disclosure and allow us a reasonable period to investigate and remediate before any public disclosure.

Contact

For security questions or to report a vulnerability:

Veyce
Email: info@veyce.com.au

Or use our contact form.