Identity and access
Map every administrator, service account, API key, organization boundary, and support-access path. Verify least privilege and removal procedures in the deployment you operate.
Healthcare deployment review
QuickVoice makes privacy-sensitive voice infrastructure inspectable. Your compliance posture still depends on how you deploy and operate it, which providers process data, which agreements are in place, and whether the full system passes security, privacy, operational, and legal review.
Review the system, not a slogan
Map every administrator, service account, API key, organization boundary, and support-access path. Verify least privilege and removal procedures in the deployment you operate.
Trace call metadata, transcripts, recordings, knowledge sources, logs, and exports from creation through backup, retention, deletion, and recovery.
Review LiveKit, telephony, speech, model, storage, email, and observability providers. Data handling and agreement requirements extend beyond this repository.
Test redaction, retention, secret handling, URL validation, tenant isolation, auditability, and failure behavior against your threat model and deployment configuration.
Document risk assessments, access reviews, incident response, workforce procedures, vendor reviews, change control, and the evidence needed for your own audit program.
Determine whether BAAs or other agreements are required with every relevant party. Have qualified privacy, security, and legal reviewers approve the production design.
Shared responsibility
Code paths, defaults, data models, permissions, logs, retention jobs, integrations, and update process.
Cloud accounts, network controls, databases, object storage, secrets, backups, observability, availability, and access administration.
LiveKit, carrier, speech, model, embedding, vector, and other services that can receive or process call data.
Policies, workforce access, risk analysis, incident response, consent, notices, vendor management, contracts, and audit evidence.
Production gate
Adapt this list to your risk assessment, jurisdiction, call flows, provider contracts, and internal control framework.
Classify the data each call flow can collect, infer, store, or disclose.
Document the exact QuickVoice commit, configuration, providers, regions, and subprocessors in scope.
Obtain and review required provider agreements before processing regulated data.
Configure authentication, authorization, network boundaries, encryption, logging, backups, and key rotation.
Set retention and deletion rules for transcripts, recordings, logs, knowledge sources, exports, and backups.
Test tenant isolation, redaction, deletion, restoration, incident response, and provider failure paths.
Publish recording, consent, caller-identification, and escalation procedures appropriate to each jurisdiction.
Complete security, privacy, legal, and operational approval before production use.
Review the repository, document gaps as issues, and involve the right legal and security owners before regulated production use.