# VoiceRun Enterprise Security Terms

Version 2026-10-01

These Security Terms supplement a mutually executed enterprise Order Form incorporating this version. They describe VoiceRun's contractual security obligations for the purchased Services. Current control descriptions, assurance materials, certification status and subprocessors are maintained at the [VoiceRun Trust Center](https://trust.voicerun.com/).

## 1 Security program and evidence

VoiceRun will maintain a documented security program with technical and organizational measures appropriate to the nature of the Services, Customer Data and relevant risks, and will perform its obligations under the DPA. The Trust Center is the authoritative source for current factual descriptions and evidence. These terms do not independently assert completion of SOC 2 or another certification, a particular insurance limit, or a certification not supported there.

The parties will identify deployment-specific commitments in the Order Form. VoiceRun will provide or make available the security description applicable at signing so that Customer can retain it with the incorporated legal versions. VoiceRun may update operational controls to address threats and technology changes, but may not materially reduce the overall protection of purchased Services during a committed term. A Trust Center edit does not silently amend the Agreement's liability, incident notice, retention, no-training or other express protections.

## 2 Access and personnel

VoiceRun will limit access to Customer Data to authorized personnel and providers with a legitimate need to perform their duties; use appropriate authentication and authorization for systems under its control; review and revoke access as roles change; and require confidentiality obligations. Customer is responsible for managing its Authorized Users and account credentials and using the security configuration features made available for its deployment. VoiceRun remains responsible for security of the platform functions it controls.

## 3 Data and service protection

VoiceRun will maintain risk-appropriate protections for Customer Data in storage and transit within systems it controls, including access controls, applicable encryption measures, logging and monitoring, vulnerability and patch management, and practices for secure development and change management. Specific control implementations and their scope are described in the Trust Center and the applicable deployment description. Telephony or Customer-controlled endpoints may have distinct capabilities; the Order Form and technical configuration identify those boundaries. VoiceRun will not represent a customer-controlled or unsupported connection as end-to-end encrypted merely because another segment uses encryption.

VoiceRun's provider diligence and contracts will support its data-protection, confidentiality and no-training obligations. The Trust Center identifies relevant Subprocessors and processing locations; the DPA governs changes, objections and transfer safeguards. VoiceRun will not use its security responsibilities as a basis for generalized training on Customer conversation content or Customer-specific artifacts.

## 4 Incident management

VoiceRun will maintain an incident-response process for investigation, containment, remediation, evidence preservation and communications, and initiate that process immediately when a security incident is identified. That operational process covers threats to confidentiality, integrity or availability; the narrower customer-notice trigger below does not limit internal incident response. It will notify Customer without undue delay and within 48 hours after confirmation of a material Security Incident affecting Customer Data, subject to any earlier or broader notification required by Applicable Data Protection Law. The DPA defines the incident, required information, ongoing cooperation and notice channels. Security incidents will be investigated promptly, and incomplete information will not delay required initial notice.

## 5 Continuity backups and deletion

VoiceRun will maintain business continuity, disaster recovery and backup practices appropriate to the purchased Services. No particular recovery-time objective or recovery-point objective is promised unless expressly stated in the Order Form. The SLA separately governs availability and permitted exclusions.

Customer-requested deletion will be completed within 30 days of a valid request; post-termination Customer Data retrieval is available for 60 days, followed by deletion. These obligations include applicable backup copies, and backup schedules do not extend a deletion deadline. DPA Section 6 governs the limited grounds for retaining security logs, incident evidence and other necessary records, including applicable-law limits, protection, purpose restrictions and eventual deletion. These periods do not permit reuse of Customer Data or Customer Models.

## 6 Assurance and testing

VoiceRun will make available the assurance and testing materials actually available through the Trust Center, subject to reasonable confidentiality and access controls. The DPA governs compliance information and any legally required direct audit. Customer may perform ordinary internal functional evaluation; penetration testing, vulnerability scanning that could affect the Services, or other intrusive testing requires VoiceRun's prior written authorization specifying scope, timing and safeguards. VoiceRun may provide available independent testing summaries as an alternative.

## 7 Shared responsibilities and changes

Customer will configure its applications, users, integrations, notices and permissions consistently with the agreed design, promptly report suspected compromise and cooperate with response. Neither party's obligations are excused by the other's responsibility for a different layer. Customer-hosted deployments require an executed Order Form rider defining infrastructure, monitoring, patching, backup and response duties, subject to the security review and scope confirmation in Section 2.3 of the Enterprise Services Agreement. Cloud-service assurance materials do not automatically extend to customer-operated infrastructure. Updates to these terms follow the Enterprise Services Agreement's version and notice protections.
