Security
What is true today, and what is still planned.
VoiceCanary is early-stage. This page separates behaviour you can verify in the demonstration from controls that belong to a production deployment.
In place in the demonstration
The public demonstration is fictional
Every transcript, tool event and appointment record on this site comes from local synthetic fixtures. No real call is placed and no patient record is read.
Evidence access is customer-approved
VoiceCanary reads only the evidence sources a customer explicitly connects for a pilot, and only for the workflow in scope.
Staging-first credentials
Pilot credentials are restricted to the staging agent and the controlled outcome source. Production credentials are not requested.
Planned production controls
Stated as requirements, not as completed or certified implementations.
Tenant isolation
Separation of customer evidence is an implementation requirement for the product, not a control we claim is independently verified today.
Retention and deletion
A real-data pilot requires agreed retention windows and a deletion path for stored evidence, defined before any data is ingested.
Service and agreement review
The exact subprocessors and agreements are reviewed with the customer before any identifiable patient information is accepted.
No certifications claimed
VoiceCanary does not hold or display security certifications, does not certify HIPAA compliance, and does not guarantee regulatory outcomes. Published legal terms and a privacy policy are not available yet; they will be published once reviewed and approved.
Discuss pilot requirements