Security
Security at Voiceflow
Trust Center
Reports, certificates, and security documentation
How we protect your data
Data protection
Data is protected with strong encryption at rest using customer-managed keys, securely backed up across regions, and stored in highly available multi-AZ databases with point-in-time recovery.
Access and application security
Application security is maintained through automated and manual code reviews, continuous vulnerability scanning, regular external penetration testing, and enterprise-grade access controls including SSO.
Infrastructure and reliability
Enterprise-grade reliability with 24x7 monitoring, multi-AZ cloud infrastructure, and annually tested disaster recovery. Built on AWS and GCP with isolated environments and Infrastructure as Code for consistent, resilient operations.
Network security
Network security is enforced through a CDN-backed WAF and DDoS protection, end-to-end encryption in transit with TLS and mTLS, and a segmented, firewalled architecture that strictly controls service-to-service communication.
Security operations
Strong security foundations with encrypted credential storage (bcrypt), audit logging and alerting, granular access controls, continuous updates, and full project history tracking with rollback capability.
Organizational security
Organizational security is reinforced through employee background checks, ongoing security training, least-privilege access controls, comprehensive audit logging, and regularly tested business continuity and disaster recovery plans.
AI data privacy
Voiceflow does not use customer data to train any machine learning or AI models.
Customer data is only used to provide and operate the service. Any model providers integrated through Voiceflow (e.g., OpenAI, Anthropic, Google) are configured with zero data retention and do not use submitted data for training.
Security resources
Responsible disclosure
If you discover a potential security vulnerability, please email security@voiceflow.com. Eligible submissions may qualify for our bug bounty program.
Voiceflow values the contributions of the security research community in helping us maintain a safe and secure platform. We provide safe harbor for good-faith security research conducted in accordance with this Vulnerability Disclosure Policy. This means that if you comply with the guidelines set forth in this policy, Voiceflow will not initiate legal action against you under the Computer Fraud and Abuse Act (CFAA), the Digital Millennium Copyright Act (DMCA), or similar laws in other jurisdictions. We ask that you refrain from publicly disclosing any potential vulnerability until our security team has had the opportunity to review and address it.