Compliance & Data Protection

What your DPO will ask, answered in plain language — and only with what is actually built.

Last updated: 29 August 2026

Biometric data is special-category data — we treat it that way

Voiceprints used to identify a person are special-category personal data under GDPR Article 9. VoiceIDVault is built consent-first: no biometric processing happens before explicit, recorded consent, and passive (continuous) voice verification is additionally gated — the API refuses to process audio for a user who has not granted separate passive-auth consent. Consent is revocable at any time, and revocation is honored at the API layer, not just in policy text.

Encryption at rest

Voiceprint vectors are encrypted with AES-256-GCM using envelope encryption (KMS-managed keys). When encryption is active, the database stores ciphertext only. Decryption failures fail closed: the system denies rather than degrades.

Right to erasure, with a receipt

Deletion is an API call, not a support ticket. The erasure endpoint removes a user's biometric data on request and the deletion is recorded, so a data subject request can be answered with evidence rather than assurances.

Tamper-evident audit trail

Security-relevant events are written to an HMAC-chained, append-only audit log — each entry incorporates the signature of the previous one, so retroactive edits are detectable. Authentication decisions, consent changes, and administrative actions leave a verifiable trail.

Fail-closed by design

Errors never grant access. If deepfake screening, decryption, or verification cannot complete, the request is denied and the fallback path (your existing process — OTP or knowledge-based checks) takes over. No caller is ever locked out by voice alone, and no error path ever approves.

Positioning with EU frameworks — stated precisely

VoiceIDVault is designed as a step-up verification layer for returning claimants, complementing — never replacing — your KYC processes or EUDI Wallet-based identity. Our architecture is aligned with eIDAS 2.0 assurance concepts; eIDAS assurance levels attach to notified national eID schemes, so we do not describe any product as “eIDAS certified.” Under the EU AI Act's distinction between biometric verification and remote biometric identification, VoiceIDVault performs verification: confirming a claimed identity with the subject's consent.

Certifications — current, honest status

SOC 2 Type II: in progress. ISO 27001/27017: in progress. We publish no accuracy or fraud-prevention percentages until independent benchmarking (e.g., ASVspoof-style evaluation) is complete. If a vendor quotes you “99.9%” without an independent benchmark, ask them for the study; we made the deliberate choice not to do that.

Questions, DPIAs, and documentation

We support customer Data Protection Impact Assessments and will answer security questionnaires with the same candor as this page — including a written list of current limitations. See also our Privacy Policy.

Talk to us about compliance