Security and compliance

Security already in place, a SOC 2 Type II report underway

Data encryption, Canadian hosting and least-privilege access protect your calls today. Drata monitors our controls continuously, and the observation period leading to the SOC 2 Type II report is underway.

Canadian French + English • Configurable human handoff • Keep your number when supported by your carrier

At a glance

Defined by the workflow, not only the voice

"Are you SOC 2?" comes up in nearly every serious evaluation. Here is a complete answer rather than a logo in a footer.

First, what protects your data right now. Traffic is encrypted in transit, service data is hosted in Canada, internal access follows least privilege, and every integration is limited to the reads and writes validated with you. These controls work today and depend on no audit.

Second, the formal programme. VocalOps has engaged Drata, a continuous control monitoring platform, and the observation period leading to a SOC 2 Type II report is underway. We are going straight for Type II because it attests to how controls operated over a period — the level buyers actually ask for.

Third, the transparency that makes the rest of it credible. The report goes up the day an independent auditor issues it, and not a day sooner. That is the commitment our security page already carries.

In the meantime there is nothing to wait for: the security documentation exists and we send it on request. A trust centre is in preparation; until then, email admin@vocalops.ca and you will get a specific, written answer.

Outcomes

What protects your data today

Written, reviewed policies

Policies with a named owner and a review schedule, rather than implicit practice nobody can produce on request.

Access management

Least privilege across internal systems, with access removed when someone leaves rather than at the next cleanup.

Continuous monitoring

Drata checks control state continuously and flags drift, instead of sampling once a year as the audit approaches.

Logging and traceability

Keeping what it takes to investigate an incident and show what actually happened, rather than reconstructing it from memory.

Vendor management

An inventory of the subprocessors that touch data, what each one handles, and a review when the list changes.

Incident response

A written process: who is notified, within what delay, what the customer is told, and who decides.

Buyer guidance

How to read an AI voice vendor’s compliance posture

Most buyers ask "are you SOC 2?" and stop at the answer. It is the least informative question on the list: it resolves to yes, and a yes says nothing about what was covered, for how long, or with which exceptions. Here is what to ask next — of any vendor, ourselves included.

A badge on a website is not a report

The only deliverable that matters is the auditor’s report, shared under NDA. A footer logo, a "trust" page with nothing downloadable, or a screenshot of a compliance dashboard are not evidence. Ask for the report; if it does not exist, ask to be told so plainly rather than left to infer it.

Type I and Type II do not say the same thing

A Type I describes the design of controls on a given date: they existed on paper that day. A Type II tests how they operated over a period, typically three to twelve months. A vendor announcing "SOC 2" without naming the type is often announcing a Type I, which is a legitimate starting point but demonstrates nothing about consistency.

Ask for the scope before the result

Only the security criterion is mandatory; availability, confidentiality, processing integrity, and privacy are optional. So a report can be perfectly clean and say nothing about the confidentiality of your data. Ask which criteria are covered and which systems are in scope — a report that excludes the product you are buying is more common than you would expect.

Read the exceptions, not the conclusion

A Type II lists the tests performed and the deviations found. That is the useful part, and it is the part nobody reads. A report with a few documented and remediated exceptions is often more reassuring than a spotless one whose scope was narrowed until it tested almost nothing.

Check the carved-out subservices

A vendor can exclude from its scope the services it depends on — the hosting provider, the telephony carrier, the language model. These are carve-outs, and it falls to you to obtain those reports and verify the complementary controls you are expected to run on your side. A clean report resting on an entirely carved-out stack covers very little.

Look at the end date, then ask for a bridge letter

A Type II report covers a period that has ended. Between its end date and today, nothing is attested. A bridge letter closes that gap by confirming no material change occurred. An eighteen-month-old report with no bridge letter is an archival document.

The vendor’s compliance is not yours

SOC 2 is an American control framework, not a privacy law. It replaces neither Quebec’s Law 25 nor federal PIPEDA, and it relieves you of no notice, consent, or register. The two subjects are handled separately, and a vendor that conflates them in its pitch is telling you a great deal.

What you can evaluate with no report at all

Data flows, retention periods, the subprocessor list, the access model, the incident process, and the configured refusals can all be checked right now, in writing. A vendor with no report that answers those six points precisely protects you better than a vendor with a badge that answers vaguely. Judge the answers, not the emblems.

Questions to ask any vendor, ourselves included

  • Is the report a Type I or a Type II, and what period does it cover?
  • Which trust services criteria are covered beyond security?
  • Which systems are in scope, and which are explicitly excluded?
  • What exceptions does the report contain, and what has been remediated since?
  • Which subservices are carved out, and which complementary controls fall to us?
  • What is the report’s end date, and is there a bridge letter?
  • Which firm performed the audit?
  • What happens if a control drifts between two reporting periods?

Implementation

The stages of a Type II report

  1. 1

    Scope

    Choose the applicable trust services criteria and define which systems are covered. A report with an unknown scope tells nobody anything.

  2. 2

    Instrument

    Connect Drata to our systems to track control state continuously and gather evidence as it accrues.

  3. 3

    Observe

    A Type II covers how controls operated over a period, not a snapshot on one date. This is the stage we are in.

  4. 4

    Audit

    An independent firm examines the evidence and issues the report. Until it is issued, there is no report — and we will say it that way.

Scenarios

What you can request today

Data flow description

What is captured during a call, where it travels, where it lands, and which systems touch it.

Retention and deletion

Durations by data type — audio, transcript, summary, customer record — and how deletion is actually carried out.

Subprocessor list

The providers involved in the processing applicable to your deployment, and what each one receives.

Data processing agreement

Contractual commitments, shared responsibilities, and notification obligations.

Incident process

Who to contact, how quickly you are notified, and what the notice contains.

FAQ

Questions about our compliance

Is VocalOps SOC 2 certified?

No. The correct word is "report" rather than "certification" in any case: SOC 2 produces an independent auditor’s report, not a certificate. We have engaged Drata and the observation period toward a Type II report is underway. No report has been issued to date.

What is the difference between Type I and Type II?

A Type I attests to the design of controls on a specific date. A Type II tests how they operated over a period, often three to twelve months. Type II is what we are working toward, because it demonstrates consistency rather than one favourable snapshot.

When will the report be available?

We do not publish a date. A missed date says more than a met one, and the schedule depends partly on the audit firm. Email admin@vocalops.ca for the current status at the moment you are evaluating; the answer will be specific and in writing.

What is Drata, and is it a certification?

Drata is a continuous control monitoring platform: it checks the state of our controls on an ongoing basis and gathers evidence for the audit. It is not an audit and it is not a certification. No vendor should present its compliance tooling’s logo as a result.

Can we get security documentation before the report?

Yes. The data flow description, retention periods, the applicable subprocessor list, the processing agreement, and the incident process are all available now on request at admin@vocalops.ca.

Does SOC 2 cover our obligations under Law 25?

No. SOC 2 is a control framework, not a privacy law. Your Quebec obligations — notice, a designated privacy officer, retention periods, an incident register — remain entirely yours. Our Law 25 page covers the ones that touch a phone line.

Where is the data hosted?

VocalOps positions on Canadian hosting. The exact residency of each component and integration has to be confirmed in your deployment documentation: some processing, notably by the voice models, may run elsewhere, and you are told so rather than left to assume otherwise.

Do you sign a data processing agreement?

Yes, and its content is discussed before the contract is signed rather than after. Send us yours if your organization requires its own template; we will say what we can commit to and what we cannot.

Will you have a trust centre?

Yes, it is in preparation and will bring the documents and control status together in one place. Until it is published, everything goes through admin@vocalops.ca.

Send us your security questionnaire

Describe the data involved and your organization’s obligations. We answer with what exists today, and we say plainly what does not exist yet.