When a clinic, a bank or a government office considers an AI voice agent, the security team usually asks the same first question: where does the call data go? A proper AI voice agent security review goes further. It covers the recordings, the transcripts and the customer records the agent touches, what the agent is allowed to do, and who at the vendor can see any of it. The checklist below gives you fifteen questions to put to any vendor.
Ask a voice AI vendor five groups of questions: data, access, how the AI behaves, operations and compliance. Good answers are specific, written down and backed by evidence such as audit reports or a named process. Vague answers and general promises of security are a warning sign.
Before you start: write a data map
Before the questions, write a simple data map. List everything that moves through the system: the caller's voice, the transcript, the details captured during the call, any customer record the agent reads or writes, recordings, logs and the summaries sent to your staff. Put the same map in front of every vendor, so each answer is about the same data.
If you are also weighing up wider buying questions, how to choose an AI voice agent platform covers them alongside this checklist.
Data: where it lives and who can use it
Data questions decide where your customers' information is kept and who can reach it. Ask for every answer in writing, and check it against the data map.
- Where is our data stored and processed? A named country or region, written into the contract, with no transfer outside it unless you approve that transfer in writing.
- Do you train your models on our calls, transcripts or records? A clear no, in writing, on every plan, with any exception switched off by default. Our own position is set out in never trained on your data.
- How long do you keep recordings, transcripts and logs, and can we set the period? A retention period we choose, deletion on request, and a written policy that covers backups.
Access: who can see and change what
Access questions decide who can hear a call, read a transcript or change how the agent behaves. Every one of those permissions should be deliberate and visible to you.
- Who at your company can listen to calls or read transcripts? Named roles only, with each access logged. No shared accounts.
- How do we control what our staff and the agent can see and change? Role-based permissions for every user, and a record of every change to those permissions.
- Do you support single sign-on and multi-factor authentication for admin accounts? Single sign-on with our identity provider, and multi-factor authentication required for every administrator.
AI behaviour: what the agent may do
These questions cover what the agent can do, what it says and how it stops. They matter most for actions that change a record, commit to a price or share information with a caller.
- What can the agent do without a person approving it? A written list of the actions it may take alone. Anything above a set limit, such as a refund or a change to a customer record, needs approval. The guardrails and approvals should be enforced by the platform, not only described in the agent's instructions.
- How do you stop the agent from making things up? Answers come from approved knowledge, bookings and prices are checked against the source system, and the agent passes the call to a person when it is not sure of an answer.
- Will the agent tell a caller it is an AI if they ask? Yes, every time. Disclosure rules vary by country and must be followed, and any change to that setting should be recorded.
Operations: how the service runs and fails
These questions cover the day-to-day running of the service and how it behaves when something goes wrong. They are easy to skip in a demo and expensive to discover later.
- How do you detect and respond to security incidents? A written incident process, the time within which you will tell us about a breach once it is found, and a named contact for out-of-hours problems.
- How is call audio and customer data protected in transit and at rest? Encryption in both states, with a clear description of how encryption keys are stored and rotated.
- Who are your subprocessors, meaning the other companies that handle your data for you, and where is each one located? A current list you can review, with notice before any change to it.
Compliance: the evidence and the contract
These questions cover the evidence and the paperwork. A good vendor can show you the evidence without a fight, and the contract should match what they tell you in the sales process.
- Can you show independent audit reports for the service we would use? Current reports whose scope covers the product we would actually use, not a different one. VoiFlow's current certifications and documents are listed in the Trust Center, so you can check them directly.
- How do you support our data protection duties where our customers live? A clear answer that names the law in each country you serve. In the UAE, for example, the Personal Data Protection Law, Federal Decree Law No. 45 of 2021, and a statement of the vendor's role for your data.
- Will you sign a data processing agreement before go-live, and what does it cover? Yes, in writing, before the pilot starts. It should cover roles, security measures, breach notice, deletion, subprocessors and audit rights. The data processing agreement page sets out how VoiFlow approaches this.
Documents to request
Ask for these before you sign, not after:
- The data processing agreement and the security terms
- The list of subprocessors and the location of each one
- The latest independent audit report, with its scope
- The retention schedule and the deletion process
- The incident response plan, including notice times
- A summary of staff and administrator access controls
- The rules and limits the agent works within, written out in full
How to score the answers
Give each answer one of three marks, and count only the answers that are clear and in writing:
- Clear and in writing. The answer is specific, names the evidence and could go into the contract.
- Clear but verbal. The answer makes sense on the call, but nothing has been sent. Ask for it in writing before you rely on it.
- Vague or missing. The answer avoids the question, changes between conversations or depends on a promise about the future.
A vendor with fifteen clear and written answers is a credible candidate. A vendor with several vague answers should not move to the next stage until those gaps are closed.
Red flags in a vendor's answers
Some answers should end the conversation, or at least trigger a closer review:
- A general claim that security is taken seriously, with no detail behind it.
- No stated hosting region, or a region that changes between answers.
- Training on customer data that is switched on by default.
- Reluctance to sign a data processing agreement before go-live.
- No way to see who listened to a call or read a transcript.
- Security described only in the agent's instructions, not enforced by the platform.
How VoiFlow handles this
VoiFlow's agents are hosted in-region and are never trained on your data. Guardrails, including permissions, limits, consent, redaction and an audit trail, are enforced outside the model. Every call is recorded, transcribed, scored and replayable, so the audit questions above can be answered from the record. The Trust Center is the place to check VoiFlow's current documents, rather than relying on a summary in this article.
Frequently asked questions
Do we need a data processing agreement?
Usually yes, when a vendor processes personal data on your behalf. Ask your legal adviser what your own obligations require, and ask the vendor for its agreement before the pilot starts.
Should call recordings be encrypted?
Yes. Recordings and transcripts should be encrypted in transit and at rest, and access to them should be limited and logged. Ask the vendor to describe how its encryption keys are managed.
Can a voice agent be secure enough for health or banking calls?
Security depends on the platform, the rules you set and how the calls are run, not on the sector alone. Health and banking often add their own rules, so check those with your compliance team and ask the vendor for evidence that matches them.
How often should we review a vendor's security?
At least once a year, and again whenever the vendor changes its subprocessors, hosting or the agent's permissions. Keep the answers to this checklist on file, so the next review starts from the last one.
To review the documents behind these answers, start with the Trust Center, or contact our team with your list of questions. This is general information, not legal advice.





