Security, Privacy and AI at VirtualSpeech
Everything your IT and procurement teams need before a rollout, in one place. Where your data is held, who can reach it, how our AI features use it, and what we have and haven't certified.
If something you need isn't here, email security@virtualspeech.com and we'll answer directly. We complete security questionnaires as standard.
Where we stand today
We'd rather you read this than find it out in a questionnaire three weeks into procurement.
| Area | Status |
|---|---|
| UK GDPR / EU GDPR | Compliant. Data Processing Agreement available. |
| EU AI Act | Built to its transparency, fairness and human oversight principles. |
| ICO registration | ZB245994 |
| Penetration testing | Annual, by a CREST-accredited firm. |
| ISO 27001 | Aligned. Certification in progress, expected Jan/Feb 2027. |
| ISO 27701 | Aligned. Not certified. |
| SOC 2 Type II | Not certified. |
| Cyber Essentials | Not yet held. Certification in progress, expected November 2026. |
| Accessibility | Partially conformant with WCAG 2.1 AA. VPAT available. |
Our platform has passed enterprise security review at organisations including Deutsche Telekom, Bayer and Swisscom. Bayer went further and connected their own internal language model to the platform.
Where we aren't certified, we provide our Data Processing Agreement, penetration test summary and this documentation to satisfy audit requirements. Most customers find that sufficient; if your procurement process requires a specific certification we don't hold, tell us early rather than late.
Where your data is hosted
All customer data is held on Amazon Web Services.
- European customers: AWS Frankfurt, Germany (eu-central-1)
- All other customers: AWS Ohio, United States (us-east-2)
Your region is set when your account is created and data stays in it. Backups are held in the same region as the live data.
A simplified network diagram is available on request.
What data we hold
Learners
- Identity. Name and email address, provided by your administrator. These can be anonymised, or we can supply generic addresses.
- Performance data. AI scores, speaking pace, hesitations, listenability, and movement metrics from VR sensors.
- Transcripts of roleplay, coaching and presentation sessions.
- Coaching plans. The written plan a learner builds during a Skills Coaching session, saved to their account.
- Audio and movement recordings. Saved only when the learner presses Save. Audio includes both the learner's voice and the avatar's. Movement data is head and hand-controller position from a VR headset, replayed so the learner can see how they moved. Saving can be switched off for your whole organisation.
- Uploaded assets. Through the upload manager, learners and administrators can add presentation slides, notes, audience questions (entered as text and voiced in the app), a CV or job description, and a thesis.
- Session names on shared headsets, typed as free text by the learner at the start of a session.
- Technical data. Device user agent, IP address in server logs, and the time the app was last used.
- Authentication data. Password hashes, or the identifier passed by your identity provider where SSO is used, and session tokens.
What your administrators can switch off
Several of the categories above are optional. From the admin dashboard, you can disable any of these for your organisation:
- The upload manager, so learners cannot upload slides, CVs or other files at all.
- Saving transcripts of sessions.
- Saving audio and body language recordings.
- Leaderboards, which otherwise show learner names to others in the same organisation.
You can also anonymise learner data, so administrators see cohort-level summaries while each learner keeps full visibility of their own results.
Your own privacy notice to learners
Administrators can replace the privacy notice and disclaimer a learner sees at first login with their own wording. If your organisation has its own data protection notice, works council agreement or learner consent language, your people see that rather than ours before they start.
Administrators
- Name, email address, role and permissions.
- Login and administrative activity.
- Scenarios your team authors in Roleplay Studio, including the character brief, situation and scoring criteria. This content is yours. We do not reuse it for other customers or to train models.
Individual subscribers
People who buy a subscription directly from our website, rather than through an organisation:
- Name, email address and purchase history.
- Payment is processed by Stripe. We do not store full card details.
Website visitors and enquiries
- Marketing website. We use Google Analytics 4 to understand how the site is used. It sets cookies and records information such as pages viewed, referring source, approximate location and device type.
- Enquiries. Demo requests, webinar registrations, resource downloads and newsletter sign-ups are held in HubSpot, our CRM.
- Correspondence. Emails you send us, and our replies.
See our Privacy Policy for cookies and marketing detail.
What we never collect
- Facial images, facial expressions or biometric identifiers.
- Emotion recognition of any kind.
- Voice pattern recognition used to identify a person. Voice is analysed for pace and clarity only.
- Camera or video footage. No webcam feed is recorded or analysed at any point.
Body language metrics are derived from VR headset and hand controller positions alone, not from AI interpretation and not from any camera. Without a headset, body language tracking is off entirely.
Encryption
- In transit: TLS 1.3 with HTTP Strict Transport Security. We hold an A+ rating from Qualys SSL Labs and publish a DNS CAA policy.
- At rest: AES-256 across databases, servers and storage. Each saved audio recording is encrypted with its own key, and that key is itself encrypted with a master key we rotate regularly.
- Passwords: hashed with PBKDF2, SHA-256 and random salts. Never stored in plain text.
- Server access: public-private key only, 2048-bit SSH-2 RSA.
Who can access your data
Four members of our technical team have production access, for debugging and customer support only. Every one of them:
- uses multi-factor authentication
- has passed a background check
- completes security training
Access is granted per resource on the principle of least privilege, managed through AWS Identity and Access Management. Amazon GuardDuty monitors continuously for malicious or unauthorised activity.
Your own administrators control what learners see and, where you enable anonymisation, whether administrators see individual results or cohort summaries only.
Penetration testing
We commission an annual authenticated penetration test of the platform from Bulletproof Cyber Limited, whose testers are CREST-accredited. Testing follows OWASP methodology and covers the authenticated web application.
The most recent test was carried out in November 2025, with a retest in December 2025 to verify remediation. Encryption was rated Strong.
A summary report is available on request under NDA.
Backups and resilience
- Backups run daily and are retained for 10 days.
- Backups are held in the same AWS region as your live data.
- Security and troubleshooting logs are kept for 90 days. Audit and compliance logs are kept for 15 months, or longer where the law requires it.
Retention periods can be shortened or lengthened to match your own compliance requirements.
What we don't offer: we do not currently publish an uptime SLA or a public status page. If uptime commitments are a procurement requirement, raise it during the commercial discussion.
Incident response
We maintain a documented incident response plan. In the event of a personal data breach, we notify the customer (as data controller) without undue delay and no later than 72 hours after becoming aware of it, and assist with notifying the supervisory authority and affected individuals where required.
AI and your data
The short version:
- Your data is never used to train AI models. Not ours, not OpenAI's, not Microsoft's.
- AI conversations and scoring run on the OpenAI API (currently gpt-realtime-2.1). European customers can be moved to Azure OpenAI in an EU region on request.
- OpenAI may retain API inputs and outputs for up to 30 days for abuse monitoring, then deletes them. We use default API settings with no persistent memory.
- Every client's data is logically separated. No client can access another client's data.
- Scores are for development only. Our contracts prohibit using them for hiring, promotion, pay or any other employment decision.
- If you run your own OpenAI-based model, we can connect it so that roleplay behaviour and feedback draw on your internal best practice. Bayer does this today.
Full detail: AI and Data Privacy
Sub-processors
| Sub-processor | Purpose | Entity and location |
|---|---|---|
| Amazon Web Services | Hosting, storage, logging and error monitoring | Amazon Web Services EMEA SARL, Luxembourg |
| OpenAI | AI conversations, scoring and feedback | OpenAI OpCo, LLC, San Francisco, USA |
| Microsoft | Azure OpenAI, for EU customers on request | Microsoft Ireland Operations Ltd, Dublin, Ireland |
| Stripe | Payment processing (individual subscriptions) | Stripe, Inc. |
| Business email and productivity | Google Ireland Ltd | |
| BunnyCDN | Content delivery | BunnyWay d.o.o., Slovenia |
| HubSpot | Customer relationship management (prospect and contact data) | HubSpot, Inc. |
All sub-processors operate under written contracts imposing GDPR-compliant safeguards. Transfers to US-based sub-processors are covered by Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum.
We notify customers in advance of any change to this list.
Retention and deletion
While you're a customer. We retain data for up to six years unless your contract specifies a shorter period. Most enterprise and education agreements set their own retention period, and we recommend agreeing one that matches your policy.
Learner and admin deletion. Learners and administrators can delete transcripts, recordings and uploaded assets themselves at any time. These are removed from the platform immediately and roll off backups within 10 days.
Deletion requests. You can request deletion or return of your data at any time by contacting your account manager or privacy@virtualspeech.com. We complete requests within 7 days.
Authentication and access
- Single sign-on via SAML 2.0, supporting both IdP-initiated and SP-initiated login, standard RelayState configuration and Single Logout.
- A staging environment is available so you can test your SSO integration before going live.
- Our SAML metadata is published at
learn.virtualspeech.com/saml2/metadata/
What we don't offer yet: SCIM automated user provisioning, and social sign-in via Google or Microsoft. User management is handled through the admin dashboard, your LMS integration, or our API.
Application and infrastructure security
- Web traffic is restricted to HTTPS, with all HTTP requests redirected. The domain is on the HSTS preload list.
- The database is reachable only from the web server.
- Administrative actions use privilege escalation rather than a root account.
- Multi-factor authentication is required for AWS.
Integrations
- LMS and VLE: Moodle, Blackboard, Canvas and others via our API or LTI. Completion data and scores flow back into your system.
- Your own AI model: connect an internal OpenAI-based LLM so feedback reflects your own guidance.
- SSO: SAML 2.0 as above.
Accessibility
VirtualSpeech is partially conformant with WCAG 2.1 Level AA. We publish an Accessibility Conformance Report (VPAT, Section 508 Edition) covering WCAG 2.0 and 2.1 Level A and AA, available on request.
Full detail: Accessibility Statement
Documents available on request
Email security@virtualspeech.com and we'll send these, under NDA where appropriate:
- Data Processing Agreement (DPA)
- Penetration test summary report
- Accessibility Conformance Report (VPAT)
- Network and data flow diagram
- Sub-processor list
- Completed security questionnaire, or we'll complete yours
Policies
Contact
Security and compliance: security@virtualspeech.com
Data protection and privacy: privacy@virtualspeech.com
Data protection lead: Dominic Barnard, Co-Founder
VirtualSpeech Ltd, registered in England and Wales, company number 09517558.
44–54 Unit 4, Coleridge Road, London N8 8ED, United Kingdom.
Registered with the Information Commissioner's Office, reference ZB245994.
Last reviewed: September 2026