Last Updated: August 12, 2026
If you believe you have found a security vulnerability in VoiceFly, email security@dropfly.io. Please include enough detail to reproduce the issue.
We will acknowledge your report within two business days. We will not pursue legal action against researchers who report in good faith, avoid accessing or modifying other customers' data, and give us reasonable time to remediate before disclosing publicly.
We triage reported and detected vulnerabilities by severity and target the following remediation windows from the point of confirmation:
Dependencies are monitored continuously for published advisories, and our source repositories are private. Where a fix is not yet available upstream, we mitigate by removing or isolating the affected path rather than waiting.
All traffic to VoiceFly is served over HTTPS with TLS. We do not offer unencrypted endpoints.
Third-party credentials you connect to VoiceFly — CRM tokens, calendar authorizations, integration keys — are encrypted at rest with AES-256-GCM before being written to the database, using a key held only in our platform's secret store and never in source control. If that key is unavailable, writes are refused rather than falling back to storing the value unencrypted.
Every account is scoped to a business. API requests are authenticated by verifying the caller's session token server-side, then confirming that the authenticated user is a member of the specific business whose data is requested — a token for one business cannot read another's.
The database enforces row-level security in addition to the application checks, so the browser-facing key cannot read records directly.
VoiceFly answers phone calls on your behalf, so we process call audio, transcripts, caller phone numbers, and any details a caller provides. We process this to deliver the service, and we do not sell it.
Call handling, transcription, and language processing are performed by the subprocessors listed below. Where that processing happens is set out in section 7.
We use the following providers to deliver the service. Each processes customer data only as needed for its function:
Everything VoiceFly stores — call records, transcripts, messages, contacts and account data — is held in a single United States region. We do not replicate customer data to other regions, and VoiceFly is currently offered to US-based businesses only.
Two subprocessors process data outside the United States, and we would rather state that than let you discover it:
Where you connect an integration, the data you direct us to send leaves our environment and enters that provider’s. Clio Grow connections are US-only.
The database is backed up daily, with seven days retained. In a disaster we would restore from the most recent backup, which means up to 24 hours of data could be lost. We do not currently offer point-in-time recovery, an uptime SLA, or a recovery time commitment — we would rather tell you that than publish a number we have not tested.
Credentials for integrations you connect are encrypted with AES-256-GCM, and the encryption key is held independently of the database so that a restore cannot leave them unreadable.
VoiceFly runs on infrastructure whose providers hold SOC 2 Type II attestations and offer HIPAA-aligned controls. VoiceFly is not itself independently SOC 2-certified or HIPAA-certified. We state this plainly because infrastructure attestations are commonly presented as if they were the vendor's own. If you intend to send protected health information, contact us about a Business Associate Agreement first.
Call recordings are deleted after roughly 14 days. Audio is held by our voice provider, not by us, and is removed on their retention schedule. We keep the transcript and summary in your account for longer so your call history stays useful, subject to a retention period you can shorten in your settings.
You can disconnect any integration from your dashboard at any time, which removes the stored credentials for it. On account closure we delete or anonymise your account data, and you may request deletion at any time by emailing support@dropfly.io.
Calls are handled by third-party voice and language providers. Under our current plan, our voice provider states that recordings, transcripts and logs may be retained to help train and improve their AI models. We are telling you this plainly because it is the kind of detail that matters and is easy to leave unsaid.
Zero-retention and HIPAA-mode processing — where the provider stores no call content at all — are available on request for customers whose obligations require it. Contact security@dropfly.io before sending sensitive matter details if that applies to you.
We maintain an internal incident response process covering detection, containment, credential rotation, and customer notification.
If a breach affects your data, we will notify you within 72 hours of confirming it, and describe what was affected, what we did, and what you should do. We commit to a specific window rather than “without undue delay” because a deadline you can hold us to is worth more than a phrase that means whatever we later decide.
Security questions, questionnaires, and diligence requests: security@dropfly.io. See also our Privacy Policy and Terms of Service.