Security & Vulnerability Disclosure
Last updated: August 11, 2026
1. Our Commitment
At VOXUB (CIRIT LLC), the security of our platform, our customers' data, and our callers' information is our highest priority. We invest in robust security measures, continuous monitoring, and rapid incident response to protect everyone who interacts with our service.
2. Reporting a Vulnerability
If you believe you have discovered a security vulnerability in VOXUB's products or infrastructure, we encourage you to report it to us responsibly. We are committed to working with security researchers to verify and remediate reported issues.
- Email your findings to security@voxub.com with a detailed description of the vulnerability, including steps to reproduce.
- Include the affected URL, component, or service, and any proof-of-concept code or screenshots.
- Do not access, modify, or delete data that does not belong to you. Do not degrade or disrupt service availability.
- Provide a reasonable timeframe (at least 90 days) for us to investigate and remediate before any public disclosure.
3. Responsible Disclosure Guidelines
To qualify for acknowledgment and potential reward, reports must adhere to the following guidelines:
- Test only on accounts and resources you own or have explicit permission to test.
- Do not exploit the vulnerability beyond what is necessary to demonstrate its existence.
- Do not access, exfiltrate, or share personal data of other users.
- Do not perform denial-of-service attacks, social engineering, or physical attacks.
- Do not use automated scanners that generate high traffic volumes against our infrastructure.
- Report vulnerabilities as soon as they are discovered — do not hold them for leverage.
4. Our Response Process
When we receive a vulnerability report, we follow this process:
- We acknowledge receipt within 48 hours and assign a tracking number.
- We investigate and validate the report within 5 business days, providing status updates as we work.
- We remediate confirmed vulnerabilities based on severity, with critical issues addressed as quickly as possible.
- We notify the reporter when the fix is deployed and coordinate public disclosure if desired.
5. Security Practices
VOXUB follows industry-standard security practices to protect our platform:
- All data in transit is encrypted using TLS 1.2+ and data at rest is encrypted in the database and object storage.
- Authentication uses signed JWT tokens with HS256; sensitive operations require additional verification.
- All API access is authenticated and authorized with role-based access control (RBAC).
- Security audit logs record all data access and administrative actions.
- Content Security Policy (CSP) headers are enforced and violations are monitored.
- Third-party sub-processors are vetted and operate under Data Processing Agreements.
- Customer call recordings are stored in encrypted S3 buckets with access-controlled proxy endpoints.
6. Acknowledgments
We are grateful to the security researchers who help us keep VOXUB safe. With your permission, we will list your name or handle here after the vulnerability has been remediated. If you prefer to remain anonymous, we respect that choice.
7. Contact
For security-related inquiries or to report a vulnerability, contact us at security@voxub.com. For privacy or data protection questions, contact
For legal matters, contact privacy@voxub.com.
Compliance & Certifications
VOXUB adheres to industry-leading compliance standards to protect your data and your customers' privacy.
- GDPR Compliant — Full GDPR compliance including data subject rights (access, erasure, portability), consent logging, Data Processing Agreements, and sub-processor management.
- CCPA Compliant — California Consumer Privacy Act compliance with opt-out mechanisms for data sale/sharing and consumer rights to know, delete, and opt-out.
- WCAG 2.1 AA — Web Content Accessibility Guidelines 2.1 Level AA compliance with 0 axe-core violations across all pages, plus an on-site accessibility widget for user customization.
- PCI-DSS via Stripe — All payment processing is handled by Stripe, a PCI-DSS Level 1 certified provider. VOXUB never stores full card numbers.
- TLS 1.2+ / AES-256 Encryption — All data in transit is encrypted with TLS 1.2+ and all data at rest is encrypted with AES-256 in the database and object storage.
SOC 2 Type II: VOXUB is currently in the SOC 2 readiness phase. Our security practices align with SOC 2 Trust Services Criteria, and we plan to initiate a formal SOC 2 Type II audit in the near future. Contact security@voxub.com for the latest status.