Where your data lives, and who can touch it
Last updated September 22, 2026
Related: Privacy policy and Terms of service.
The short version
- Your data stays in the United States. We name the hosting provider below and disclose every vendor that touches it.
- Nothing Vocartes drafts is sent, published, filed, or paid without a named person at your business approving it first.
- We do not delete your records because you downgrade a plan, hit a usage limit, or fall behind on payment. Deletion happens on your written request, or when law requires it.
- We do not use your data to train any AI model, ours or anyone else's, and our contracts with model providers say so.
- We don't accept protected health information and we don't sign Business Associate Agreements. That's a deliberate scope decision, not a gap. Healthcare and dental practices are welcome for everything else.
- We don't have a SOC 2 report yet. The SOC 2 section below says exactly where that stands.
- Records are deleted two months after cancellation. You can export everything before then, and nothing is deleted early because of a plan downgrade or a missed payment.
Where your data lives
Vocartes runs on US data centers only. We host with a single named infrastructure provider rather than spreading data across several, and we'll name that provider here once it's locked in.
Your data does not leave the United States. If a vendor we use is based outside the US, we'll name that vendor and its location plainly in the subprocessor list below, not fold it into a general statement.
Protected health information: a deliberate scope, not a gap
Vocartes does not accept protected health information, and we do not sign Business Associate Agreements. This is a deliberate choice about what the product is for, not a security shortcoming we intend to fix later. If a BAA program ever becomes a roadmap item, that would be a separate, explicit decision we'd announce before accepting any clinical healthcare data, not something implied by anything on this page today.
If you run a healthcare or dental practice, you're welcome to use Vocartes for your website, marketing, hiring, vendor and lease contracts, bookkeeping at the practice level, and tracking license and insurance renewals. You should not use Vocartes for anything that touches a patient's chart, diagnosis, treatment, prescription, insurance claim, or appointment and recall list, or any communication that identifies a named person as your patient. See Terms: no protected health information for the full definition and what happens if this information is submitted by mistake.
Encryption, in transit and at rest
Every connection between you, Vocartes, and any system we connect to on your behalf runs over TLS. We'll state the exact minimum version here once engineering confirms it in production, rather than round up.
Data at rest is encrypted. We'll name the exact standard and algorithm here once that's confirmed, and nowhere on this page will you find a phrase like "military-grade encryption." We'd rather name the standard than describe it.
Who can access your data
Access to customer data inside Vocartes is role-based and limited to what a person's job actually requires. We're building logging for every internal touch of customer data; until that's live, access is limited by role and by need, not yet backed by a full audit trail.
Right now, the team with production access is small, background-checked, and under a signed confidentiality agreement, and we review who holds that access on a regular cadence. We are not yet at the point of a full internal audit log, and we've said so above rather than implying otherwise.
We do not send customer data to offshore contractors without disclosing it here first.
Subprocessors, including model providers
Every vendor that touches your data gets named here, not described in general terms. That includes our cloud host, our AI model provider or providers, our email delivery service, and anything else with access to customer data. Today that list includes:
- Our cloud hosting provider (named above, once confirmed)
- Our AI model provider or providers (to be named here, along with the no-training commitment below)
- Our email and communication delivery vendor
This is the sentence we mean to keep, not just publish: Vocartes does not use your business data, your customers' data, or your communications to train any AI model, ours or any third party's, and we contractually prohibit our model providers from training on your data.
We'll keep this list current, and we'll notify you before adding a new subprocessor with material access to your data.
The human approval gate
Nothing Vocartes drafts is sent, published, filed, or paid without a named person at your business approving it first, unless you've explicitly configured a narrower set of pre-approved, reversible actions.
Approval means you see the actual content or action itself, not a summary of it, before it happens. You can edit or reject it at that point.
What's gated by default: anything that leaves your business. Emails and texts to your customers, published web content, filings, payments, and contracts all wait for your approval. What isn't gated by default: routine internal drafts, analysis, and dashboards you're only using to see what's going on.
This is the reason we can be direct about liability: since nothing goes out without you reviewing and releasing it, what goes out is yours. See Terms: the approval gate for exactly how that responsibility works.
Data retention
We do not delete your business records, communications, or historical data because you downgrade a plan, hit a usage limit, or fall behind on payment. Plan limits affect how much new work runs at once. They never trigger deletion of anything Vocartes has already created or stored for you.
General business records are kept for the life of your account, plus two months after cancellation. During those two months you can export everything; after them, we delete it. We don't shorten that window to enforce a plan limit, and falling behind on payment doesn't trigger deletion inside it either. Records tied to regulated industries, such as legal records, are kept for as long as your own recordkeeping duty requires, commonly 7 to 10 years depending on your state and profession, unless you direct earlier deletion in writing and confirm it's legally permitted.
Deletion happens on your explicit written request (subject to you confirming it doesn't violate your own recordkeeping obligations), or when the law requires it. It does not happen because of non-payment or a plan downgrade.
Export and what happens on cancellation
You can export your data (documents, records, communication history, structured data) in a usable format at any time, including after you've given notice to cancel. Export is available within a set number of business days of your request; we'll publish that number once engineering confirms it.
Canceling doesn't delete your data immediately. It's retained per the section above. Access to the live product ends, but export, and where applicable the published website content you own, stays available to you. See Terms: who owns what.
Breach notification
If a breach affects your data, we'll notify you without unreasonable delay, and in any case within the timeframe your state's breach-notice law requires. Most US state laws land somewhere between "without unreasonable delay" and a 30 to 60 day outer bound depending on the state, and we'll meet whichever deadline is earlier, including any that your own regulatory obligations impose. We aren't going to promise a specific hour or day number here unless our incident response process actually operates to that standard, because a promise we can't keep is worse than an honest range.
SOC 2 status
Vocartes has not completed a SOC 2 audit. We do not describe ourselves as "SOC 2 compliant," because a compliance claim without a completed attestation is a certification claim we can't back yet. We're building our controls environment toward a SOC 2 Type I audit, and we'll publish a target date here once it's set, followed by Type II. Once a report exists, we'll publish it, or a summary suitable for prospective customers.
Reporting a vulnerability
Found a security issue? Email . We'll acknowledge good-faith reports within 2 business days, and we won't pursue legal action against a researcher who follows responsible disclosure. We don't currently run a paid bug bounty program.