Skip to main content

Security & Compliance

Security is built into every layer of Movoice AI. Voice AI handling customer conversations requires the highest level of data protection and regulatory compliance.

Data Encryption

  • At Rest: Encryption at rest is provided by our storage and database providers at the platform level, rather than configured per object by our own code. See section 11 of the Privacy Policy.
  • In Transit: All data between your app, our servers, and AI providers is secured via TLS 1.2+.

Provider Security

We partner only with infrastructure providers that maintain rigorous standards:

Compliance Standards


Data Residency

Movoice does not offer customer-selectable data residency, and operates no regional clusters.
  • Call recordings, voicemail, encrypted message media and archived transcripts: object storage in the United States.
  • Primary database: hosted outside India.
  • Other processing: across our sub-processors in India, the United States, the European Union and Singapore — and China only where the mainland-China voice endpoint is selected for speech synthesis or voice cloning.
Section 8 of the Privacy Policy describes the categories of sub-processors we use and is the operative statement on where data is processed. The full named list is available to customers on request at legal@movoice.ai. See also Data Residency.

Admin Security Features

  • API Key Scoping: Create keys with limited permissions (e.g., read-only access to transcripts).
  • Audit Logs: Administrative actions on your account — including agent changes, deletions, exports and role changes — are logged with a timestamp and the acting user. Records are retained for five years and cannot be altered by customers.
  • Auto-Deletion: Optional. Retention is off unless you turn it on, applies to your whole account, and cannot be set below 30 days.
  • SSO: SAML-based Single Sign-On is on the roadmap and is not available today.
To report a security vulnerability, contact security@movoice.ai.