Back to Blog
Compliance & Security

Voice AI vendor security questions: what evidence to request

Ask how caller data moves, who can access it, how external actions are authorized and how incidents or deletion requests are handled.

Burki
(Updated: September 25, 2026)
3 min read

Evaluate a voice AI vendor using the conversation you intend to run. A public-information receptionist, a healthcare intake line and a payment flow have different data and authorization needs. Begin with the smallest permitted scenario and ask for evidence against it.

Map where a call's information goes

Ask the vendor to identify the carrier, media service, speech/model providers, transcript store, optional recordings and every connected tool. Include logs, exports, backups and support access. Record the relevant regions and retention choices for each copy.

“Bring your own key” usually describes provider credentials. It does not demonstrate that all processing stays inside your network or cloud account. Verify that distinction before choosing BYO for privacy reasons.

Ask questions that can be demonstrated

AreaQuestionUseful evidence
Tenant isolationCan another workspace retrieve this call or recording?An authorized denial test with synthetic records
CredentialsWhere are provider keys stored and who can use them?Access policy, rotation procedure and the actual runtime boundary
ActionsCan the assistant invoke only the tools assigned to it?A permitted action and a rejected unassigned action
RecordingWho enables it, how is consent handled and who can play it?The selected configuration and authorized playback behavior
DeletionWhich copies are deleted, retained or managed by another processor?Documented procedure and verified result for a test record
IncidentsWho notifies whom and what information is supplied?Contractual process, responsible contacts and escalation route

A transcript of an assistant saying “deleted” or “booked” is not proof that the underlying action completed. Inspect its actual result.

Review independent and contractual evidence

Request applicable security reports and read their service scope and dates. A SOC 2 report is not a universal certification, and a vendor's infrastructure-provider report does not automatically cover its application.

For regulated data, establish which laws and agreements apply to the actual relationship. Use the HIPAA deployment review or GDPR data lifecycle guide where relevant. Do not accept a free-plan label as evidence that a BAA, data-processing agreement or particular hosting arrangement exists.

Keep a written acceptance record

For each requirement, record the observed evidence, owner and open issue. Separate “configured,” “tested” and “contractually committed.” Review the list again when adding a model provider, enabling recording or introducing a new business action.

Burki's draft editor and browser tests let you evaluate behavior using fictional information. They do not establish a security certification or authorize production handling of sensitive caller data. Start with a business assistant draft only within the data and action scope your team has approved.

Ready to try Burki?

Create an assistant and check your available browser practice allowance.

Create your assistant

Trial eligibility and available practice are shown in your workspace.

Related Articles