Security

How we handle your audio, your account, and your incidents.

Vocaler is in private beta. This page is the security posture today and a roadmap to where it needs to be before general availability.

Compliance posture

Data handling

Sub-processors

A current list of vendors that touch tenant data. Updated when the list changes; we email Studio and Enterprise tenants 30 days before any addition.

Vendor Purpose Region
AWS (S3, RDS)Storage and databaseeu-west-1, us-east-1
CloudflareCDN, DNS, Pages hostingGlobal
StripeBillingUS, IE
ReplicateAI music + motion inferenceUS
TailscaleMac render-farm VPNGlobal
ResendTransactional emailEU

Incident disclosure

Responsible disclosure

Found a vulnerability? Email security@vocaler.ai with reproduction steps. We respond within 2 business days and credit reporters in the changelog once the issue ships a fix.

Audit + SOC 2 readiness

Studio and Enterprise tenants can request our current SOC 2 readiness summary, sub-processor list with up-to-date attestations, and pentest report at security@vocaler.ai. Documents are shared under NDA.