Security and data handling
Clear controls for a sensitive first point of contact.
Law firms should understand what a phone service receives, where it goes, who can access it, and how long it remains available.
Reviewed and updated July 26, 2026 by the VoiceOrbit product team.
Short answer
VoiceOrbit uses firm-scoped accounts, capability-protected public demos, request throttling, restricted website fetching, verified telephony callbacks in production, and minimized routine analytics. Recording, transcript, notification, and retention settings are agreed before live traffic.
Access and isolation
Customer sessions are authenticated and tied to a firm. Portal reads and writes are scoped to the firm, while administrative access is separated. Public demo access uses an expiring capability instead of a guessable public record.
Network and request safeguards
Production Twilio webhooks require signature verification. Public demo creation is throttled, and website ingestion blocks private and link-local network targets to reduce server-side request forgery risk.
Data minimization
Marketing analytics use named funnel events and avoid form contents, audio, and transcripts. Routine logs are designed to avoid full call content. Production data fields are used to operate intake, routing, review, security, and billing.
Providers and retention
Core providers include OpenAI for AI processing, Twilio for telephony, SendGrid for email, PostHog for privacy-limited analytics, and hosting/database infrastructure. Retention and deletion requirements for paid service should be defined in the order form.
Current assurance posture
VoiceOrbit is an early commercial product. It does not claim completed certifications or controls that are not in place. Firms with specific vendor-risk, data-residency, insurance, or contractual requirements should raise them before enabling production calls.
Common questions
What law firms ask before launch
Is VoiceOrbit SOC 2 certified?
Not currently. VoiceOrbit does not claim SOC 2, HIPAA, or another certification that has not been completed. Security requirements should be reviewed during procurement and documented in the customer agreement.
Does the public demo use confidential data?
It should not. The demo uses a firm’s public website and fictional caller details. Visitors are instructed not to submit privileged communications, medical records, real case details, or other confidential information.
Is every call recorded?
No. Recording is an explicit configuration decision. The firm is responsible for selecting a lawful recording and notice policy for the jurisdictions and calls it serves.