VAPT programDPDP-readyGDPR toolingSOC 2-ready exports

Security and trust, built into every conversation

From TOTP MFA and SAML/OIDC SSO to per-data-class retention, on-call consent capture, and recording redaction that runs before transcripts touch storage — this is how Zoice protects your customers' data at every layer.

Identity & Access

Access & Authentication

Control who gets in, what each role can touch, and how long a session lives — set once at the organisation level.

TOTP multi-factor authentication

Enrol in seconds with a QR code in any authenticator app — with one-time backup codes for a lost device.

Org-wide security policy

Force MFA for every member, restrict sign-ins with an IP allowlist, and cap session length across the org.

Custom roles (RBAC)

Compose roles from a permission catalog — page-level permission gates hide anything a role can't act on.

SAML / OIDC single sign-on

Bring Okta or Azure AD — Zoice serves SP metadata so identity-provider setup is copy-paste.

SCIM provisioning

Issue SCIM provisioning tokens so your IdP creates, updates, and deactivates Zoice users automatically.

Visibility

Audit & Monitoring

Every action your team takes is recorded, diffable, and streamable into your own tooling.

Full audit log

Every org action is recorded and filterable by action, resource, actor, and date range.

Before / after diffs

Click any audit row to see exactly what changed — the before and after of every update, side by side.

Audit-log streaming

Stream audit events to external sinks like your SIEM — a delivery inspector shows what was sent and whether it landed.

Your Data, Your Rules

Data Governance

Retention, deletion, residency, and exports built for GDPR and DPDP workflows.

Retention windows per data class

Separate windows for conversations, recordings, and audit logs — auto-purge enforces them, and manual purges report exact deletion counts.

GDPR delete-my-data

Erase by phone number or session ID — choose delete, or mask to redact PII while keeping aggregates for reporting.

Data residency selection

Choose the region where your organisation's data is stored.

PII-redacted PDF exports

Share conversation exports outside the platform with PII already redacted in the PDF.

Compliance export packs

One-click SOC 2-ready and GDPR compliance bundles — evidence collected and packaged for your auditor.

Built Into the Agent

Agent-level Compliance

Compliance isn't a report you run later — it happens live on the call, before data ever reaches storage.

DPDP / TCPA consent capture

Outbound calls capture an explicit yes/no consent in the first 5 seconds, recorded against the call.

PCI / DPDP recording redaction

Selectable patterns — Aadhaar, PAN, OTP — are redacted before transcripts ever touch storage.

Hallucination detection

Flags agent responses that aren't grounded in your knowledge base, so reviewers can catch drift early.

Knowledge-base citations

Grounded answers cite the knowledge-base source they came from — every claim is traceable.

Under the Hood

Encryption & Infrastructure

Secrets, media, and payloads are encrypted or signed at every hop.

Integration tokens sealed at rest

WhatsApp and Slack tokens are encrypted at rest and never displayed again after you save them.

Write-only SIP credentials

SIP passwords are never returned by the API — set them, use them, never read them back.

SRTP media encryption

Call media is encrypted with SRTP, negotiated via SDES or DTLS.

Signed webhooks

Every webhook payload is signed so you can verify it came from Zoice — with built-in signing-secret rotation.

TLS in transit

Traffic between your browser, our APIs, and your integrations travels over TLS.

Security Testing

A regular VAPT program

Zoice runs recurring vulnerability assessment and penetration testing across the application and its APIs.

Vulnerability assessment & penetration testing

A regular VAPT program probes the platform the way an attacker would — not just automated scans.

Application and API coverage

Testing spans the web application and its APIs — the same surfaces your team and your customers touch.

Recurring, not one-off

Security testing runs as an ongoing program, so new releases keep getting the same scrutiny.

Third-party certification details will be published on this page once a certificate is issued.

Responsible Disclosure

Report a vulnerability

Found something that doesn't look right? We want to hear about it — security reports go straight to the engineering team.

info@zoice.ai
  • Include clear reproduction steps and the affected endpoint or page.

  • Don't access, modify, or retain data that isn't yours while testing.

  • Give us reasonable time to remediate before any public disclosure.

Security — Frequently Asked Questions

Security review? Bring your checklist.

Walk through our controls with your team

From SSO and audit-log streaming to retention windows and consent capture — we'll map every control on this page to your compliance requirements.

ZOICE