← Back to the blog

Voice AI security checklist: what to demand from vendors

Clay diorama of Peach, the PeachDesk mascot, holding a teal shield beside a clay vault door and padlock

What does a serious voice AI security review cover?

A serious voice AI security review covers seven areas: certifications and attestations, data residency and storage control, encryption at rest and in transit, identity and access management, retention and deletion, AI governance, and vulnerability disclosure with an incident process. In every area, evidence beats adjectives: a dated audit report, a scoped certificate, or a live trust center entry is worth more than any marketing claim.

This checklist is written for procurement teams, security reviewers, and founders who need answers they can defend internally. Paste the questions into your RFP or security questionnaire as they are, and score the responses against the evidence column. If you are new to how a voice agent moves data between stages, read our overview of voice agent architecture first; the security questions below map directly onto that pipeline.

What should a voice AI compliance checklist include?

It includes seven review areas, each phrased as a question with a named evidence standard, so answers can be scored rather than admired.

Checklist areas and evidence standards compiled from ISO/IEC 27001:2022, the AICPA Trust Services Criteria, ISO/IEC 42001:2023, and Regulation (EU) 2024/1689 (the EU AI Act), accessed 2026-08-05.
Review areaQuestion to askWhat strong evidence looks like
Certifications and attestationsWhich certifications and attestations do you hold, and what is the scope and expiry of each?A certificate from an accredited body or an attestation report from a CPA firm, scoped to the product you are buying, in date, and shared under NDA on request.
Data residency and storage controlWhere are recordings, transcripts, and call metadata stored, and can we choose or control the location?A documented storage architecture, region or self-hosting options, and a precise statement of which providers and sub-processors touch call data at each pipeline stage.
Encryption at rest and in transitIs call data encrypted at rest and in transit, including credentials, recordings, and browser media?Written confirmation covering databases, object storage, provider credentials, and media transport, with named mechanisms such as TLS, signed URLs, and short-lived credentials.
Identity and accessDo you support SSO, SAML, and MFA, and how are team roles and API keys managed?Documented SSO, SAML, and MFA support with clear plan availability, defined team roles, and organisation-scoped API keys issued from a dashboard.
Retention and deletionCan we set retention windows for recordings and transcripts, and how is deletion enforced?Configurable per-agent retention windows with automated purge, described in product documentation rather than promised on a sales call.
AI governanceHow do you govern the AI systems themselves, and what is your EU AI Act readiness?An AI management system aligned to ISO/IEC 42001:2023 and a stated EU AI Act programme with current status, even where final audits are still in progress.
Vulnerability disclosure and incident processDo you publish a security policy with a private disclosure channel, and how do you handle incidents?A published security policy, a private reporting channel for researchers, and a named incident response process you can review before signing.

The table is deliberately vendor-neutral. Use it to score every platform on your shortlist with the same ruler, including us. A vendor that answers with documents in a week is telling you something different from a vendor that answers with a slide.

How do you read vendor compliance claims correctly?

Read every compliance claim as a statement about evidence: what artifact exists, who issued it, what scope it covers, and whether it is current.

Three verbs get blurred in vendor copy. Certified means an accredited third party audited the organisation against a standard and issued a certificate, as with ISO 27001. Attested means an independent auditor examined the controls and issued a report, as with SOC 2 Type 1 and Type 2. Controls in place, final audit in progress means the controls exist and operate, but the independent examination has not concluded; honest vendors say exactly this rather than borrowing credibility from a finished audit they do not yet have.

  1. Level 1 · WeakestMarketing adjectivePhrases like "enterprise-grade security" with no artifact behind them.
  2. Level 2Static policy PDFSelf-declared, often undated, and silent about scope.
  3. Level 3Attestation reportAn independent CPA examination, scoped and dated, as with SOC 2.
  4. Level 4Accredited certificationA certification body, a defined scope, and an expiry date, as with ISO 27001.
  5. Level 5 · StrongestLive trust centerCurrent status and documents, updated as audits complete, including programmes still in progress.

The ladder runs from weakest evidence to strongest. A live trust center beats a static PDF because it shows status as of today: what is certified, what is attested, and what is honestly still in progress. A PDF from three years ago can be accurate and still mislead you about the present.

Why is voice AI security different from ordinary SaaS security?

Because a voice AI platform handles live audio, recordings, transcripts, and phone numbers, and each pipeline stage can send data to a different provider, the data map is wider than a typical SaaS application.

A document tool has one storage story. A voice agent has one per stage: speech-to-text, the language model, and text-to-speech can each route to a managed provider, your own provider keys, or self-hosted inference, while telephony carriers carry the call itself. A meaningful residency answer is therefore stage by stage, not a platform-wide slogan. Our data residency page shows what that precision looks like in practice, and the deployment options determine how much of the map sits inside your own environment.

Where does PeachDesk stand on this checklist?

PeachDesk is built by Bibha, and here is the current verifiable standing, mapped row by row. Where something is still in progress, we say so.

  • Certifications and attestations. Bibha, the company behind PeachDesk, is ISO 27001 certified and SOC 2 Type 1 and Type 2 attested. Live status, scope, and documents are published at the Bibha AI Trust Center.
  • AI governance. GDPR, UK GDPR, ISO/IEC 42001:2023, and EU AI Act controls are in place, with final audits in progress. The Trust Center reflects each audit as it completes.
  • Identity and access. SSO, SAML, and MFA are available on the enterprise plan. Team roles (owner, admin, member) with granular feature access control are built in, and you create organisation-scoped API keys from the dashboard.
  • Data residency and storage. Call recordings and transcripts live in object storage the deployment controls, behind signed, time-limited URLs. The full platform also runs self-hosted from Docker Compose when you want every stage inside your own environment.
  • Encryption and transport. Provider credentials and webhook secrets are encrypted at rest, webhooks are HMAC-signed, and browser call media uses short-lived TURN credentials.
  • Retention and deletion. You set configurable retention windows per agent, with automated purge.
  • Disclosure and isolation. A published security policy with a private disclosure channel exists, and tenant isolation is enforced in code and guarded by a CI test.

What we do not claim: HIPAA. If your evaluation requires it, we will tell you plainly what is and is not available rather than stretch a claim. For the full control overview, see how PeachDesk approaches security, and for term definitions used across this checklist, the voice AI glossary.

Peach, the PeachDesk mascot, holding a ring of keys

How should you score the answers you get back?

Score evidence, not language: a dated, scoped artifact from a named third party scores full marks, a control described in documentation scores partial marks, and an adjective scores zero.

Red flags in a vendor response:

  • Certificates or reports with no scope, no date, or no issuer.
  • "Compliant with" phrasing that never names a report or auditor.
  • Refusal to share anything under NDA before signature.
  • A residency answer that cannot say which providers touch call data at each stage.

Green flags:

  • A live trust center with current documents and honest statuses.
  • Plain statements about what is certified, what is attested, and what is still in progress.
  • Retention, encryption, and identity controls described in public documentation, not only in sales material.

Put this checklist to work

Bring your security questionnaire to a demo, or read our security overview first. We answer every row with documents, not adjectives.

What security questions should I ask a voice AI vendor?

Ask seven groups of questions: which certifications and attestations the vendor holds and what scope they cover; where recordings and transcripts are stored and who controls residency; whether data is encrypted at rest and in transit; how SSO, SAML, MFA, roles, and API keys work; how retention and deletion are configured and enforced; how the vendor governs its AI systems, including ISO/IEC 42001 and EU AI Act readiness; and whether it publishes a security policy with a private vulnerability disclosure channel. For every answer, ask for the artifact: a dated report, a certificate, or a live trust center entry.

Is SOC 2 enough for a voice AI platform?

SOC 2 alone is not enough. A SOC 2 Type 2 report attests that a service organisation's security controls operated effectively over a period, which is a strong baseline. It does not by itself answer where your call recordings live, how retention works, or how the vendor governs its AI systems. Treat SOC 2 as the entry ticket, then evaluate data residency, retention and deletion, identity controls, and AI governance separately.

What is the difference between ISO 27001 certified and SOC 2 attested?

ISO 27001 is a certification: an accredited body audits the organisation's information security management system against the standard and issues a certificate with a defined scope and expiry date. SOC 2 is an attestation: a CPA firm reports on controls against the AICPA Trust Services Criteria. Type 1 covers control design at a point in time; Type 2 covers operating effectiveness over a period. Both are meaningful evidence, and neither is a guarantee on its own.

How do I verify a voice AI vendor's compliance claims?

Ask for the artifact behind every claim: the certificate or audit report, under NDA if needed. Check three things on it: the scope (does it cover the product you are buying), the dates (is it current), and the issuer (an accredited certification body or a CPA firm). Prefer vendors that publish a live trust center, because a trust center shows status as of today, including programmes still in progress, while a static PDF ages silently.

Talk to an expert

Tell us about your calls and we will come back with a straight answer on fit, sourcing, and deployment. Your message goes to the team at sales@bibha.ai.

Start free

Tell us where to reach you and what you are building, and we will set up your workspace access. Your message goes to the team at sales@bibha.ai.