Security and Data

Patient Data and Access Separation

How VOXEN separates clinic data, manages staff access, and logs actions in the system.

What's protected

Six layers of separation

Access is restricted at every layer: between clinics, between products, between roles, and within recordings.

  • Separation between clinics

    Separation at the application and database level: requests are scoped by organization and user role, plus PostgreSQL Row-Level Security policies.

  • Role-based access

    Staff see only what they need for their job. Access is determined by role and connected product.

  • Call Center and SPP are separated

    Separate roles and permissions: access to one product doesn't grant access to the other.

  • Call recordings

    Access to recordings is role-based. Patient consent is logged and can be withdrawn.

  • Action log

    We log significant changes and admin actions: who changed data or settings and when, system sign-ins, data exports.

  • Staff access management

    When an employee leaves, their account is deactivated and an administrator revokes their sessions.

Data location

Data hosted within Kazakhstan

VOXEN's infrastructure is hosted within the Republic of Kazakhstan, in line with the legal requirement to store personal data in a database located in the country.

We'll answer your security team's questions

Access separation, action logs, data location — all tailored to your specific requirements.

Request a demo