Last updated June 23, 2026
VOpilot holds the financial and contact details of your voiceover business, so protecting that data is core to the product. This page is a plain-English summary of how we do that. It complements our Privacy Policy.
Every account is walled off from every other account at the database level using row-level security — the isolation is enforced by the database itself, not just by application code, so one customer can never read another's jobs, clients, invoices, or income. The public demo site you can publish only ever exposes what you explicitly put on it, never your private account data.
In transit: all traffic to and from VOpilot is encrypted with TLS (HTTPS).
At rest: the database and file storage are encrypted at rest by our infrastructure providers.
Field level: particularly sensitive values (such as connected-inbox tokens) are additionally encrypted at the application level, so they aren't readable even in a raw database export.
Access to production systems is restricted to the minimum number of people needed to run the service, protected by multi-factor authentication. We don't read your business content in the ordinary course of operating VOpilot.
And we make that verifiable to you: whenever our team accesses your account — for a support request you raised, or to investigate a security issue — the access is written to an access log you can review yourself, any time, under Settings → Privacy & security. If no one has accessed your account, the log says so. We believe you shouldn't have to take our word for it.
We want to be straightforward with you about something most services leave unsaid. Any cloud product that actually does something useful with your information — organizes it, reads the emails you forward, builds your invoices, totals your income — has to be technically capable of reading that information in order to do its job. A service that was completely blinded to your data simply couldn't offer those features. The same is true of nearly every tool you already trust: your email provider, your accounting software, your bank's app.
So the question worth asking isn't whether a provider could technically access your data — realistically, every one can — but whether that access is kept minimal, controlled, and accountable. That is the standard we hold ourselves to: we don't read your business content in the ordinary course of running VOpilot, access is limited to the narrow circumstances above, and whenever it does happen, you can see it for yourself in your access log. We would rather earn your trust with something you can verify than with a promise no honest provider could keep.
When you get paid through VOpilot, Stripe and PayPal handle your card and bank details directly — VOpilot never sees or stores full card or bank-account numbers. You are the merchant of record, and funds settle directly to your own connected account.
If you reconcile deposits by importing a bank statement CSV, that file is parsed and matched entirely in your browser — it is never uploaded. Only when you confirm a match does VOpilot record that one payment's amount and date against the record; the rest of the statement, including account numbers and every unmatched line, never leaves your device.
Your data is backed up by our database provider so it can be recovered in the event of a failure or accidental loss. Infrastructure is hosted on established cloud platforms with their own physical and network security.
We rely on a small set of vetted providers to run VOpilot, each under contracts that limit their use of your data:
If we become aware of a security breach affecting your personal data, we will notify affected users and any required authorities without undue delay, consistent with applicable law.
If you believe you've found a security issue, please email support@vopilot.co with the details. We welcome responsible disclosure and will work with you to confirm and address it.
If your organization requires a signed Data Processing Addendum (DPA), see our DPA or contact us at support@vopilot.co to execute one.
VOpilot is built and run with care, but we don't overstate our posture: we are a focused product, not a large enterprise with formal third-party certifications (such as SOC 2 or ISO 27001) at this time. What we can show you is concrete and verifiable — the controls above, and the access log in your own settings. We'll keep strengthening this as we grow.