Skip to content

Security & trust

How we protect your voice, your content and your account

A plain description of what Vocla does today, what is available on request, and what we have not done yet. No badges we haven't earned.

  • In place

    Encryption in transit

    Connections to vocla.ai, the Vocla app and the API are served over HTTPS (TLS). Session cookies are HTTP-only and marked secure on HTTPS, and browser requests that change data are protected against cross-site request forgery.

    • HTTPS for the website, app and API
    • HTTP-only, secure session cookies
    • CSRF protection on account actions
  • In place

    File storage

    Uploads and generated audio are stored in Cloudflare R2, which encrypts all stored objects at rest. Private files are never public: the app hands out signed links that expire, by default after 15 minutes.

    • Stored on Cloudflare R2
    • Encrypted at rest by the storage provider
    • Short-lived signed download links
  • In place

    Account security

    Passwords are stored only as Argon2 hashes. You can turn on two-factor authentication with an authenticator app, review and sign out active sessions, and receive email alerts for new sign-ins. Changing your password signs out your other sessions.

    • Argon2 password hashing
    • Optional two-factor authentication (TOTP)
    • Session list, remote sign-out and login alerts
  • In place

    Access control and audit logs

    Every request is checked against the workspace it belongs to, so one customer can never read another's files. Inside Vocla, staff access is role-based (support, finance, content, operations) with the least access each role needs, and every administrative change is written to an audit log that cannot be edited.

    • Workspace isolation on every request
    • Role-based staff permissions
    • Immutable audit log of admin actions
    • Support access is time-limited, read-only and notifies you
  • In place

    API keys

    Enterprise workspaces can create API keys with specific scopes (for example, generations or voices only). The full key is shown once when it is created; Vocla stores only a hash of it. Keys can be revoked at any time.

    • Scoped keys
    • Shown once, stored as a hash
    • Revocable by workspace admins
  • In place

    AI provider processing

    To generate speech, music or transcripts, the text and audio you submit are processed by third-party AI providers, such as Google Cloud, through Vocla's own engine. Provider credentials stay on our servers and never reach your browser. Enterprise customers can request the list of providers involved.

    • Processing only to produce what you requested
    • Provider keys kept server-side
    • Provider list available on request
  • In place

    Payments

    Payments are handled by Dodo Payments, which acts as merchant of record and processes your card or wallet details on its own checkout. Vocla never receives or stores your full card number. Payment events reach us through signed webhooks.

    • Hosted checkout by Dodo Payments
    • No card numbers stored by Vocla
    • Signed payment webhooks
  • In place

    Abuse prevention and provenance

    Text is checked against blocked patterns before generation, and the API applies rate limits. We keep a fingerprint registry of audio generated on Vocla, which helps us answer whether a clip was made here. Voice cloning is consent-based: you may clone only your own voice or a voice whose owner has given you explicit permission, cloned voices stay private to your workspace, and we remove voices and suspend accounts that break the rules. Voice design creates new voices from a description, and its style references never copy a real person's identity.

    • Pre-generation moderation
    • Rate limiting
    • Fingerprint registry of generated audio
    • Consent-based voice cloning
  • In place

    Your data and your rights

    You can download or delete your generations at any time, export your account data from settings, and delete your account. How long history is kept depends on your plan; on the Free plan, generation history is kept for 30 days.

    • Self-service data export
    • Account deletion
    • Plan-based retention

Certifications and compliance

Vocla does not currently hold third-party security certifications such as SOC 2 or ISO 27001, and we will not display any until an audit is complete. We are working toward alignment with the Saudi and UAE personal data protection laws; the formal review is in progress. Our Privacy Policy explains how personal data is used today.

  • SOC 2Not yet
  • ISO 27001Not yet
  • Saudi and UAE PDPL reviewNot yet

For security and procurement teams

Enterprise customers can request the following. Some items are prepared case by case, so please allow time in your procurement timeline.

  • Security questionnaire

    We answer your standard questionnaire honestly, including the items we don't meet yet.

    Available on request
  • Data processing agreement

    A DPA covering how we process personal data on your behalf.

    Available on request
  • Sub-processor list

    The infrastructure and AI providers involved in serving your workspace.

    Available on request
  • Data residency discussion

    Where your files and data are stored, and what options exist for your requirements.

    Available on request

Responsible disclosure

If you believe you have found a security vulnerability in Vocla, please tell us privately so we can fix it before it is exploited.

  1. 1

    Email a description, the steps to reproduce and the impact you observed.

  2. 2

    Only test against your own account and data. Do not access, change or delete other people's data.

  3. 3

    Do not run denial-of-service, spam or social-engineering tests.

  4. 4

    Give us reasonable time to fix the issue before sharing it publicly.

We aim to acknowledge reports within three business days and will keep you informed as we fix the issue. We do not run a paid bug bounty at the moment.

Report a vulnerability by email

legal@vocla.ai

Questions about security?

Talk to us before you buy. We'd rather tell you what we don't do yet than have you find out later.