Security overview · reviewed September 7, 2026

Security controls.
Clear boundaries.

A factual overview of controls implemented in the current VoxaPulse product and the responsibilities that remain with service providers, deployment operators, and customers.

Live media

Consent-controlled audio

VoxaPulse requires an in-product audio-processing choice before a participant's microphone stream is used for live interpretation. Chrome and Google Meet remain separate services with their own permissions and controls.

AI processing

OpenAI processes live content

During live interpretation, microphone audio and generated text are transmitted to the OpenAI API to produce transcription, translation, and translated audio. OpenAI's handling of that content is governed by the applicable provider terms and the data controls configured for the VoxaPulse OpenAI account.

VoxaPulse storage

Raw audio is not a saved meeting record

The current VoxaPulse application is designed not to retain raw meeting audio after live processing. Temporary processing or retention by an external provider is governed separately and is not represented here as VoxaPulse transcript storage.

Optional records

Transcript storage requires consent

Transcript text is saved only when the required participant choices authorize it. Saved transcripts are normally retained for 30 days unless deleted sooner. Live translation can continue when transcript storage is not authorized.

Customer separation

Tenant-scoped application access

Organization-owned records use organization-scoped application checks and PostgreSQL row-level security policies. Sensitive administrative operations require an MFA-verified session and a recorded operational purpose. These controls reduce risk; they do not make unauthorized access impossible.

Credentials

Provider secrets stay server-side

The OpenAI API key is read by the server-side media worker and is not issued to the browser extension. Google refresh tokens are encrypted with AES-256-GCM before database storage. Infrastructure and key management remain deployment-specific responsibilities.

Data location

Location depends on the data flow

Primary service data is hosted in Hetzner FSN1 (Falkenstein, Germany). Application hosting and external-provider processing are separate: OpenAI, Google, Stripe, and other providers may process information in other locations. Any customer-specific residency requirement must be confirmed in a signed agreement.

Assurance boundary

What this overview does not claim

This page is a current product overview, not an independent audit, certification, warranty, or guarantee that a security incident cannot occur. A certification or contractual control applies only when it is identified in current written evidence or a signed agreement.

Questions or concerns

Review the controls that matter to your organization.

Contact VoxaPulse before purchase if you need a security review, deployment-specific data-flow information, or written contractual commitments.

Contact VoxaPulse