Security & trust
How we protect your voice, your content and your account
A plain description of what Vocla does today, what is available on request, and what we have not done yet. No badges we haven't earned.
- In place
Encryption in transit
Connections to vocla.ai, the Vocla app and the API are served over HTTPS (TLS). Session cookies are HTTP-only and marked secure on HTTPS, and browser requests that change data are protected against cross-site request forgery.
- HTTPS for the website, app and API
- HTTP-only, secure session cookies
- CSRF protection on account actions
- In place
File storage
Uploads and generated audio are stored in Cloudflare R2, which encrypts all stored objects at rest. Private files are never public: the app hands out signed links that expire, by default after 15 minutes.
- Stored on Cloudflare R2
- Encrypted at rest by the storage provider
- Short-lived signed download links
- In place
Account security
Passwords are stored only as Argon2 hashes. You can turn on two-factor authentication with an authenticator app, review and sign out active sessions, and receive email alerts for new sign-ins. Changing your password signs out your other sessions.
- Argon2 password hashing
- Optional two-factor authentication (TOTP)
- Session list, remote sign-out and login alerts
- In place
Access control and audit logs
Every request is checked against the workspace it belongs to, so one customer can never read another's files. Inside Vocla, staff access is role-based (support, finance, content, operations) with the least access each role needs, and every administrative change is written to an audit log that cannot be edited.
- Workspace isolation on every request
- Role-based staff permissions
- Immutable audit log of admin actions
- Support access is time-limited, read-only and notifies you
- In place
API keys
Enterprise workspaces can create API keys with specific scopes (for example, generations or voices only). The full key is shown once when it is created; Vocla stores only a hash of it. Keys can be revoked at any time.
- Scoped keys
- Shown once, stored as a hash
- Revocable by workspace admins
- In place
AI provider processing
To generate speech, music or transcripts, the text and audio you submit are processed by third-party AI providers, such as Google Cloud, through Vocla's own engine. Provider credentials stay on our servers and never reach your browser. Enterprise customers can request the list of providers involved.
- Processing only to produce what you requested
- Provider keys kept server-side
- Provider list available on request
- In place
Payments
Payments are handled by Dodo Payments, which acts as merchant of record and processes your card or wallet details on its own checkout. Vocla never receives or stores your full card number. Payment events reach us through signed webhooks.
- Hosted checkout by Dodo Payments
- No card numbers stored by Vocla
- Signed payment webhooks
- In place
Abuse prevention and provenance
Text is checked against blocked patterns before generation, and the API applies rate limits. We keep a fingerprint registry of audio generated on Vocla, which helps us answer whether a clip was made here. Voice cloning is consent-based: you may clone only your own voice or a voice whose owner has given you explicit permission, cloned voices stay private to your workspace, and we remove voices and suspend accounts that break the rules. Voice design creates new voices from a description, and its style references never copy a real person's identity.
- Pre-generation moderation
- Rate limiting
- Fingerprint registry of generated audio
- Consent-based voice cloning
- In place
Your data and your rights
You can download or delete your generations at any time, export your account data from settings, and delete your account. How long history is kept depends on your plan; on the Free plan, generation history is kept for 30 days.
- Self-service data export
- Account deletion
- Plan-based retention
Certifications and compliance
Vocla does not currently hold third-party security certifications such as SOC 2 or ISO 27001, and we will not display any until an audit is complete. We are working toward alignment with the Saudi and UAE personal data protection laws; the formal review is in progress. Our Privacy Policy explains how personal data is used today.
- SOC 2Not yet
- ISO 27001Not yet
- Saudi and UAE PDPL reviewNot yet
For security and procurement teams
Enterprise customers can request the following. Some items are prepared case by case, so please allow time in your procurement timeline.
- Available on request
Security questionnaire
We answer your standard questionnaire honestly, including the items we don't meet yet.
- Available on request
Data processing agreement
A DPA covering how we process personal data on your behalf.
- Available on request
Sub-processor list
The infrastructure and AI providers involved in serving your workspace.
- Available on request
Data residency discussion
Where your files and data are stored, and what options exist for your requirements.
Responsible disclosure
If you believe you have found a security vulnerability in Vocla, please tell us privately so we can fix it before it is exploited.
- 1
Email a description, the steps to reproduce and the impact you observed.
- 2
Only test against your own account and data. Do not access, change or delete other people's data.
- 3
Do not run denial-of-service, spam or social-engineering tests.
- 4
Give us reasonable time to fix the issue before sharing it publicly.
We aim to acknowledge reports within three business days and will keep you informed as we fix the issue. We do not run a paid bug bounty at the moment.
Questions about security?
Talk to us before you buy. We'd rather tell you what we don't do yet than have you find out later.