Security

Security at Vomyra

Voice agents handle real conversations and real customer data. Here's how Vomyra keeps that data protected across authentication, encryption, and access control.

Authentication & access control

All calls and API access are scoped to your account and authenticated with API keys or OAuth 2.1. Credentials can be rotated at any time, and access is limited to the scopes each integration needs.

Role-based access control lets teams grant the right level of access per member, with audit logs recording who did what — controls that matter for regulated industries such as BFSI and healthcare.

Encryption

Call recordings, transcripts, and customer data are encrypted in transit (TLS) and at rest. Data moving between the agent and your connected systems — CRM, calendar, or any REST API — travels over encrypted channels.

Data handling

You control what the agent collects and where it writes. Call outcomes can be pushed to your own CRM or spreadsheet, and you decide retention for recordings and transcripts.

Vomyra processes personal data on your behalf as described in our Data Processing Agreement. See the DPA for roles, sub-processors, and international-transfer safeguards.

Telephony & carriers

Bring your own carrier (Plivo, Twilio, Telnyx) and route calls over your own SIP trunk, or use Vomyra-provided numbers. Either way, call signaling and media are handled over secure connections.

Reporting a vulnerability

If you believe you have found a security issue, please email security@vomyra.com with details so our team can investigate and respond. We appreciate responsible disclosure.