Security
Last updated: July 25, 2026
This page describes how BhaShaVox approaches security. It is provided for transparency and does not constitute a warranty or contractual commitment unless separately agreed in writing. We hold no third-party security certification at this time; where we describe an industry practice, we describe what we do, not an audited standard.
Our Security Approach
BhaShaVox processes sensitive user content including text, audio, video, and voice recordings. We design our systems with security and privacy in mind and work continuously to reduce risk as the platform evolves.
We are an early-stage company and we do not currently hold SOC 2, ISO 27001, or similar third-party certification. We describe our actual practices below rather than claiming compliance we have not been audited against. If your procurement process requires a certification or a completed security questionnaire, contact security@bhashavox.com and we will tell you honestly where we stand.
We are not a HIPAA Covered Entity or Business Associate and we do not currently sign Business Associate Agreements, so the Services should not be used as the system of record for protected health information without your own risk assessment. Similarly, we are not a certified processor under any sector-specific regime such as PCI DSS; card payments are handled entirely by our payment provider.
Security is a shared responsibility: please use a strong, unique password, keep your credentials and API keys confidential, and only upload content you are authorised to process.
Infrastructure & Hosting
The Services run on established cloud infrastructure providers whose data centres maintain physical and network security controls and their own independent certifications. We do not operate our own data centres.
Production environments are separated from development and staging, network access to production systems is restricted, and administrative access requires authentication over encrypted channels.
Encryption
In transit. Traffic between your browser or app and our servers is encrypted using TLS (HTTPS), as is traffic between our services and the AI and infrastructure providers we use.
At rest. Our managed databases, object storage, and backups are encrypted at rest using the encryption provided by our cloud platform.
Credentials. Passwords are stored using a strong one-way hashing algorithm with per-user salting, never in plain text and never in a recoverable form. API keys are stored hashed and shown to you only once at creation.
We do not offer end-to-end encryption: content must be decrypted to be translated or synthesised, so it is processed in memory by our systems and by the AI providers acting on our behalf.
Access Controls
Access to production systems and customer data is limited to the team members who need it for their role, on a least-privilege basis. Administrative access is authenticated, individually attributable, and logged.
Your content is not routinely accessed by our staff. Access happens only where necessary to investigate a support request you raised, to investigate suspected abuse or a security incident, or to diagnose a fault we cannot otherwise reproduce.
Application Security
We follow secure development practices including peer code review, dependency and vulnerability monitoring, input validation and output sanitisation, rate limiting, and automated testing. We monitor for abuse, suspicious activity, and unauthorised access attempts.
AI processing of your content is carried out to deliver the features you request. We do not use private customer content to train our own models, and we operate our AI sub-processors on commercial terms that do not use customer content for public-model training, as described in our Privacy Policy.
Sub-processors & Vendor Management
We rely on third-party providers for cloud hosting, AI model inference, transactional email, and payment processing. Each is engaged under written terms that include confidentiality and security obligations and restrict use of data to the purposes we specify.
A current list of sub-processors, with the purpose and processing region for each, is in our Sub-processors notice, and is also available on request from security@bhashavox.com. Customers under a Data Processing Agreement receive advance notice of changes.
Incident Response
We maintain an internal process for detecting, investigating, and responding to security incidents, including containment, assessment of impact, and remediation.
If we become aware of a security incident affecting your personal information, we will investigate promptly and notify affected users and the relevant regulators within the timeframes required by applicable law, including notification to CERT-In where applicable in India.
Responsible Disclosure
If you believe you have found a security vulnerability in BhaShaVox, please report it to security@bhashavox.com with enough detail for us to reproduce it.
Safe harbour. If you make a good-faith effort to comply with this policy during your research, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue quickly.
In scope: bhashavox.com, our web and mobile applications, and our public APIs.
Please do not: access, modify, or destroy data belonging to other users; run denial-of-service, load, or spam tests; use automated scanners that degrade the Services; attempt social engineering against our staff or customers; or publicly disclose an issue before we have had a reasonable opportunity to fix it.
We aim to acknowledge reports within 3 business days and to keep you updated on progress. We do not currently operate a paid bug bounty, but we are glad to credit researchers who report responsibly.
Contact Us
Security inquiries and vulnerability reports: security@bhashavox.com
Privacy and data protection: privacy@bhashavox.com
Entity: BHASHAVOX PRIVATE LIMITED, Yamuna Nagar, Haryana, India
Have Questions?
Security questions or vulnerability reports? Contact us — we take security seriously.
Contact Us