Verlingo
Voice Chat Solutions Pricing Blog Contact
Sign in Start free
Verlingo
01 Voice 02 Chat 03 Solutions 04 Pricing 05 Blog 06 Contact
Sign in Start free trial
$0 per resolution
2 min to deploy
Back to Verlingo

Trust & Security

Last updated August 23, 2026
Summary: Your data is encrypted in transit and at rest, never used to train any AI model, and processed only by providers under contract with us — including Business Associate Agreements with our AI and cloud infrastructure providers. Enterprise customers handling protected health information can sign a BAA with us and run voice lines in HIPAA mode.
On this page
1. Our Approach 2. Infrastructure & Encryption 3. AI Providers & Your Data 4. HIPAA & Business Associate Agreements 5. Voice & Call Data Controls 6. Access Controls & Authentication 7. Data Retention & Deletion 8. GDPR & CCPA 9. Certifications & Roadmap 10. Reporting a Vulnerability

1. Our Approach

Verlingo answers phone calls and chat conversations on behalf of businesses in regulated industries — patient billing, dental practices, collections, utilities, legal intake. The people on those calls share names, balances, account numbers, and health details. We designed the platform around one assumption: every conversation may contain sensitive data, so every conversation gets the same protections.

  • Encryption everywhere: TLS 1.3 in transit, AES-256 at rest
  • No model training: your data is never used to train any AI model — ours or our providers'
  • Contracted processors only: every provider that touches conversation data is under a data processing agreement with us; our AI and cloud infrastructure providers additionally operate under Business Associate Agreements
  • Configurable retention: you decide how long recordings and transcripts live — including not at all
  • Shared responsibility, stated plainly: we tell you exactly what the platform enforces and what remains your compliance program's decision — no blanket claims

2. Infrastructure & Encryption

2.1 Hosting

The platform runs on Google Cloud, in US data centers. Google Cloud maintains its own extensive compliance portfolio (including SOC 2 and ISO 27001) and operates under a Business Associate Agreement with us.

2.2 Encryption

  • In transit: all connections — browser, API, telephony, and webhooks — use TLS 1.3
  • At rest: databases, file storage, and backups are encrypted with AES-256
  • Payments: card data is handled entirely by Stripe, a PCI DSS Level 1 provider; card numbers never touch our servers

2.3 Network & Monitoring

  • Firewalled infrastructure with intrusion detection
  • Automated security monitoring and alerting
  • Full audit logging of administrative and account activity

3. AI Providers & Your Data

Conversations are processed in real time by large language models. Two things matter about how that happens:

BAAs are in place with our AI and cloud infrastructure providers — including Google Cloud and xAI. The providers that process conversation content are contractually bound to HIPAA business-associate obligations, so protected health information is covered through the full processing chain, not just at our edge.

  • No training: per our agreements, providers do not use your data to train their models
  • Transient processing: conversation content is sent to AI providers only to generate the live response
  • Your knowledge base stays yours: documents you upload power your agents only — never other customers', never a general model

4. HIPAA & Business Associate Agreements

There is no official "HIPAA certification" — any vendor claiming one is overstating. What a covered entity actually needs from a vendor is a signed BAA, real safeguards, and a covered subprocessor chain. Here is exactly where we stand on each:

4.1 What we provide

  • A BAA with you — available on Enterprise plans. We act as your business associate for conversations that involve protected health information.
  • A covered subprocessor chain — our AI and cloud infrastructure providers (Google Cloud, xAI) operate under BAAs with us.
  • HIPAA mode for voice lines — one switch that stops recordings, transcripts, and call logs from being stored on the platform (see Section 5).
  • Identity verification gates — agents confirm caller identity before any account or health detail is discussed, following scripts your compliance team approves.
  • Audit trails and retention controls — every call is reason-coded and logged to your policy.

4.2 What remains yours

HIPAA compliance is a property of your whole program, not of any single vendor. Your organization remains responsible for its own policies, workforce training, risk analysis, and for configuring the platform — scripts, retention, escalation rules — to match your compliance posture. We build for that review, and your compliance team approves every script before a patient hears it.

Handling PHI? Talk to us about an Enterprise plan with a BAA before going live. Agents deployed on non-Enterprise plans are not covered by a BAA and should not be used for workflows involving protected health information.

5. Voice & Call Data Controls

5.1 HIPAA mode

For sensitive lines, HIPAA mode changes what the platform keeps:

  • No call recordings stored on the platform
  • No transcripts stored on the platform
  • No call logs retained beyond operational necessity
  • Reports and outcomes still flow to your own systems via webhooks — your records live where your compliance program governs them

5.2 Standard controls on every line

  • Recording and retention configured per line, to your policy
  • Automatic PII redaction
  • Deterministic escalation rules the agent cannot talk its way around

6. Access Controls & Authentication

  • Role-based access control: team members see only what their role allows
  • Two-factor authentication for account access
  • SSO (SAML) and SCIM provisioning on Enterprise contracts
  • Least-privilege internally: production access is restricted, logged, and reviewed

7. Data Retention & Deletion

Retention is configurable per plan and per line — see the schedule in our Privacy Policy. In short:

  • Conversation history retention varies by plan (30 to 365 days), and can be shortened — or, in HIPAA mode, eliminated
  • On account termination, active data is deleted within 90 days and backups purged within 180 days
  • You can export your data at any time, and request deletion at any time

8. GDPR & CCPA

  • We do not sell personal information.
  • GDPR: a Data Processing Agreement with Standard Contractual Clauses is available for customers processing EU personal data
  • CCPA/CPRA: California rights — access, deletion, correction — are honored for all users
  • Full details, including your rights and how to exercise them, are in our Privacy Policy

9. Certifications & Roadmap

We believe a trust page should say what is true today, not what sounds good:

  • In place today: BAAs with our AI and cloud infrastructure providers (Google Cloud, xAI); customer BAAs on Enterprise plans; DPA with SCCs; encryption, RBAC, 2FA, and audit logging as described above
  • Inherited from our infrastructure: Google Cloud's SOC 2, ISO 27001, and related attestations cover the infrastructure layer we run on
  • On our roadmap: our own SOC 2 Type II attestation — contact us for current status or to receive our security documentation

10. Reporting a Vulnerability

If you believe you've found a security issue in Verlingo, we want to hear about it. Contact us with the details and we will respond promptly. Please don't access data that isn't yours, degrade the service, or publicly disclose an issue before we've had a reasonable chance to address it.

For security questionnaires, BAA requests, or a deeper architecture review with your compliance team, contact sales — walking compliance reviewers through the platform is a normal part of how we onboard regulated customers.

© 2026 Verlingo. All rights reserved.  ·  Home · Privacy Policy · Terms of Service
Verlingo

AI voice and chat agents that handle the routine, escalate the rare, and never lose context.

Product
Voice agents Chat agents Knowledge base Integrations Changelog
Solutions
Debt collection Patient billing & RCM Property management Utilities & municipal Legal intake Home services Dental & aesthetics
Resources
Blog Docs Status API reference Guides Customer stories
Company
Partners About Careers Trust & Security Contact sales
Legal
Privacy Terms
© 2026 · All rights reserved.