Full-Time

Member of Technical Staff

Vapi

Vapi

51-200 employees

Platform for building voice AI agents

Compensation Overview

$200k - $270k/yr

San Francisco, CA, USA

Hybrid

Hybrid work in San Francisco.

Category
DevOps & Infrastructure (1)
Software Engineering (1)
Required Skills
Bash
Kubernetes
GitHub Actions
TypeScript
AWS
Go
Terraform
DevOps

Get referred to Vapi

See people who can refer or advise you

Requirements
  • Treat internal engineers as customers by defining service-level agreements, documentation, and feedback loops for the developer platform.
  • Operate Pulumi with TypeScript or Terraform at scale across 40 or more stacks and multiple regions.
  • Run ArgoCD or an equivalent GitOps system for deploying applications across multiple clusters.
  • Build and operate progressive delivery in production, including canary releases, blue/green deployments, automated rollback, and soak periods.
  • Design continuous integration and continuous delivery pipelines, preferably with GitHub Actions, for many services and Dockerfiles.
  • Build deployment tooling for on-demand environments, including preview environments, development deployments, or cell creation.
  • Use TypeScript as the primary language for Pulumi and tooling, with Go for platform services and Bash.
  • Operate Kubernetes on Amazon Elastic Kubernetes Service across multiple clusters and regions.
Responsibilities
  • Own progressive delivery end to end for critical service paths, including canary releases, automated rollback, and soak periods.
  • Ship cell-creation tooling or preview environments.
  • Improve deployment-pipeline speed using lead time and mean time to recovery for failed deployments as measures.
  • Roll out progressive delivery as the default across services.
  • Establish service-level agreements and feedback loops with engineering teams.
  • Own the developer-platform roadmap and partner with Infrastructure and Site Reliability Engineering on cell creation, multi-region rollouts, and on-call tooling.
  • Become fluent in the Pulumi stacks, ArgoCD setup, and GitHub Actions pipelines.
  • Identify the top deployment pain points among the agents and field-facing development engineering teams and deliver a deployment-pipeline quality-of-life improvement.
Desired Qualifications
  • Write Go for platform services, including the canary-manager service.
  • Operate developer platforms at a mid-stage infrastructure-heavy company or work on a developer-experience team at a larger company.

Vapi provides an infrastructure platform to build and deploy enterprise-grade voice AI agents. Developers use flexible APIs and an SDK to create, test, and deploy voice agents for inbound and outbound calls, using a mix of STT, LLMs, and TTS from integrated or third-party providers to deliver low-latency conversations. Clients can bring their own API keys or use Vapi's models, giving control over cost and performance across industries like healthcare, finance, and travel, from startups to Fortune 500s. The goal is to simplify building scalable voice operations and enable rapid deployment of AI-powered call workflows, with a usage-based pricing model per minute plus telephony and AI costs, differentiating itself through a developer-centric approach and provider-agnostic orchestration.

Company Size

51-200

Company Stage

Series B

Total Funding

$70.1M

Headquarters

San Francisco, California

Founded

2021

Get referred to Vapi

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • August 2026 launches improve reliability, reducing deployment fear for enterprise buyers.
  • May 12, 2026 Series B raised $50 million, funding engineering and go-to-market expansion.
  • Ring, Intuit, and New York Life validate enterprise demand and shorten sales cycles.

What critics are saying

  • June 3, 2026 npm worm exposed weak GitHub access controls and credential hygiene.
  • Amazon Ring concentration creates brutal renewal risk if Ring shifts volume to Bland or Retell.
  • Voice agents face API commoditization as OpenAI, ElevenLabs, and telecom stacks bundle similar workflows.

What makes Vapi unique

  • Model-agnostic voice infrastructure lets teams swap STT, LLM, and TTS providers freely.
  • Vapi Simulations, launched August 18, 2026, tests agents with realistic caller personalities.
  • Production-data model intelligence uses over one billion calls to guide latency and quality choices.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Company Equity

401(k) Company Match

Growth & Insights and Company News

Headcount

6 month growth

78%

1 year growth

78%

2 year growth

128%
Vapi
Aug 18th, 2026
Vapi simulations: test for every type of caller.

Vapi simulations: test for every type of caller. Vapi Editorial Team - Aug 18, 2026 To help teams ship voice agents they can trust, Vapi, Inc. is launching Vapi Simulations, a native, AI-powered testing feature. Simulations puts AI testers on the other end of the call, each with a distinct personality and a scenario drawn from your real customers. They hold actual conversations with your agent, and every run comes back with clear pass/fail results, a full transcript, and a recording. With this new feature, you can feel confident in your deployment by validating an agent before it's in production, catching regressions after every change, and knowing it handles edge cases. Here's why Vapi, Inc. built it, how it works, and what it changes for you. Why Vapi, Inc. built it. Most teams find out their voice agent has a problem from production. A customer complains, or a conversion metric slips, and someone pulls call recordings to figure out what happened. By then, the issue has already cost you brand trust, revenue, and time spent tracking down specific conversational failures. For enterprises, that risk holds back scale. Nobody rolls a voice agent out to their full call volume without a systematic way to prove it works first. Until now, testing meant placing manual calls, which works for one agent and one change, and stops working the moment you have ten agents and a prompt update shipping every week. There's no easy way to spot a regression aside from calling your own agent and hoping you covered the right paths. Evals are still the right tool for controlled validation, but they run mock conversations with predefined message sequences, and a predefined script can't capture what real callers do. Real callers interrupt. They give you a date in the wrong format, change their mind halfway through, and get frustrated when the agent asks them to repeat themselves. Simulations closes that gap natively. Build, test, iterate, and monitor in one platform, with the full context of your agents behind every test, against the complexity real callers actually bring. How it works. Simulations are built from a few different configurations: Personalities define who's calling your agent. Each one is a full mock configuration, with its own model, voice, and system prompt. An "impatient customer" who interrupts long responses. A confused first-time caller who needs everything repeated. You design testers around the customer types you actually see, including the ones who might give your agent the hardest time. Scenarios define what the caller wants and how you measure success. Each scenario pairs tester instructions ("try to book an appointment for a date that isn't available") with evaluations: structured outputs extracted from the conversation and compared against expected values, so every run produces an explainable pass or fail rather than a "sounds good" vibe. Simulations and suites put them together. A simulation pairs one scenario with one personality; a suite groups related simulations so you can re-run your whole coverage after any change. Runs execute against the assistant or squad you are testing, and you watch results come in live. Two details make this work for real-world testing. Tool mocks let you simulate API responses at the scenario level, so you can test how your agent handles a calendar API error or a timeout without breaking anything real. And two testing modes let you match cost to purpose: chat mode runs conversations as text for fast, cheap iteration, while voice mode runs the full audio pipeline with recordings for end-to-end validation before you ship. For teams that want testing in their deployment pipeline, you can create runs through the API, with quality gates that block a deploy when pass rates drop. The quickstart and advanced guide cover setup step by step. What you can do with it. Validate before launch. An engineer is about to deploy a patient intake agent that should hand off to a nurse when a caller gets frustrated. She runs the frustrated-caller simulation, confirms the agent makes the transfer as intended, and ships knowing that path works. Catch regressions after changes. A PM updates a lead-qualification prompt to handle a new pricing objection. The simulation suite flags that the agent now skips the eligibility confirmation step. She adjusts the prompt, the test passes, and the change ships without a regression reaching callers. Prove your guardrails hold. A healthcare compliance team needs confidence that its support agent never references medication dosages or gives clinical advice. They run guardrail-specific simulations against those boundaries and keep the passing runs as a record of exactly what was tested. Test failure paths you can't produce on demand. An engineer wants to know how her scheduling agent behaves when the calendar API fails. She mocks an error response and discovers the agent tells the caller the appointment was booked. She fixes the error handling and re-runs to confirm before the change goes live. Get started. Simulations are live in your dashboard. Start in chat mode with a smoke test against an agent you already run, then build out the personalities your customers actually bring. The quickstart will get your first run finished in minutes. Know your agent works before your customer finds out it doesn't

Vapi
Aug 6th, 2026
Driving the future of Voice: Meet Vapi's New VP of Product.

Driving the future of Voice: Meet Vapi's New VP of Product. Vapi Editorial Team - Aug 06, 2026 A few months ago, Nathalie Criou joined Vapi as VP of Product. Her path here runs through nearly every seat in a technology company: software engineer, marketer, seller, product manager at Google, founder, and product and general management leader at VMware, Amazon, Twilio, and Docker. She's built at every scale, from a startup she founded and sold to leading teams and functions at some of the largest tech companies in the world. She came to Vapi because she believes voice is the channel that many businesses gave up on, and that with AI, there is an opportunity to transform the way people interact with it. A few months in, Vapi sat down with her to talk about her career, why she picked Vapi, her product philosophy, and what keeps her motivated. Tell Vapi a bit about yourself and your career path leading up to Vapi. I started as a software engineer working in signal processing. I liked the work, but I realized I was too far from customers. I wanted to get closer to people actually using what I built. I wanted to understand their problems and build platforms to drive solutions. So I moved through technical marketing, then product marketing, then spent a year in technical sales. None of it was quite the right fit, so I went to business school to figure it out. That's where I found product management. After my MBA, I joined Google, where I was part of the team integrating DoubleClick after the acquisition. I also worked at AdMob, another startup Google later acquired. Then I founded my own company, RidePal, and sold it roughly four years later. From there I kept going: Apteligent, which was acquired by VMware, then VMware itself, Amazon, Twilio, and Docker. Engineering, go-to-market, founding, general management, at companies of every size. That's the arc that led me here. What made Vapi stand out when you were deciding on your next move? Three reasons. First, the opportunity in the industry is enormous. Your upside is proportional to the size of the market you're in, and the chance to have meaningful impact here is real. Second, the channel itself matters to me. Voice is inclusive, low-friction, and highly effective. But businesses created such terrible experiences around it that humans abandoned it. Now the technology exists to fix that, and being part of that reversal is compelling. Third, the founders. They have a rare combination of genuine empathy and sheer ambition. Deeply human and intensely driven at the same time. You don't find that pairing often. What excites you most about joining a company at this stage? Where do you see voice AI heading? Voice AI is one of the few AI applications with demonstrated, repeatable ROI, and it can only improve from here. Here's the thing most people miss: current call volumes are artificially low. Companies minimize them to cut costs and reduce friction. Remove that constraint and the number of conversations should explode. Anyone who wants to talk to a company should simply be able to pick up the phone. One of its customers, Kavak, is a case study in what that transformation looks like. They started by using voice AI to augment one existing use case and got immediate ROI. Then they followed the business logic and customer demand, and within six months the entire company had reorganized around voice as a primary channel. I expect that pattern to repeat at any company where voice can play a central role in how they serve customers. The companies that lean in early will find voice becoming a core channel, not a supplementary one. How do you approach setting product priorities when different types of customers need different things from the platform? Being a platform is an advantage here. Every improvement benefits all users, and there's a natural feedback loop built in. In a market this large, even missteps can turn into learnings. There's no wrong answer. Vapi historically focused on developer experience, and that drove its early growth. But developers represent roughly 1% of the workforce. The addressable audience is much larger than what Vapi has served so far. What's changing is that AI is removing the friction that used to force non-technical teams to route through marketing, email, or other filters to reach their customers. Those teams can now engage customers directly and trust the platform to protect the customer experience. That means non-technical users increasingly need to interact with the platform, which requires a higher level of abstraction. The interesting part is that less technical users vary in sophistication, but they have the same clarity about outcomes and success metrics as developers do. The product challenge is meeting them where they are without compromising what makes the platform powerful for technical users. The AI space moves fast. How do you build a roadmap when the underlying technology keeps shifting? Start with what won't change. AI will continue to grow; the train doesn't stop, and use cases will compound. What I call market physics stays constant no matter how fast AI moves. Companies still need to grow revenue or cut costs, and AI helps with both, sometimes simultaneously. As a PM, you stay anchored to customer problems: what's the single biggest growth opportunity, what's the single biggest cost to eliminate, and what's getting in the way of either. The danger is treating AI as the end goal rather than the means. The goal of technology should be to solve a customer pain point. The discipline is to stay focused on the problem and let AI be the tool to help solve it, rather than the goal in itself. Near term, the economics favor fine-tuning for specific, narrow applications. Current models are still expensive and inefficient. I expect more integration between AI systems, and likely a unified data plane for shared context across models. What's one belief you hold about building products that most PMs would disagree with? Some product leaders might actually agree, but for many it is counterintuitive: Product management is not about managing a product. It's about managing an opportunity. Organizing teams around existing products or features is a mistake, because it shifts the incentive from the problem to the solution. A team anchored to a product is incentivized to maintain and defend it, not to question whether it's still the best answer. Organize around problems instead, and teams stay relevant. They can discover bigger opportunities customers didn't know they had, and they can find better ways to solve existing problems without being constrained by what already ships. Ownership of what exists still matters, but it shouldn't be the organizing principle. What do you do outside of work that keeps you grounded? Anyone who knows me, or has talked to me for even a few minutes, will know the answer pretty quickly: sailing and cats. No hesitation on either.

Vapi
Jul 21st, 2026
Introducing Vapi Model Intelligence: model recommendations backed by production data.

Introducing Vapi Model Intelligence: model recommendations backed by production data. Vapi Editorial Team - Jul 21, 2026 To help builders get started faster and ship better agents, Vapi Inc. is launching Vapi Model Intelligence, a bundle of features that make it easier to choose the right model combination for your use case. Model Presets are curated configurations of transcribers, LLMs, and voice models that are already selected for you and tuned to specific goals, such as low latency or high intelligence. Additionally, updated model performance metrics display current cost, latency, and quality data for every model in the catalog based on Vapi production data, so you can see the trade-offs between models and be better equipped to pick the best models for your use case. Both are built on the same foundation: the production data from the calls running through Vapi every day. Here's why Vapi Inc. built it, how it works, and what it changes for you. Why Vapi Inc. built it. The number one question Vapi Inc. get from builders, in webinars, in the community, in support tickets, is the same: "Which models should I use?" Builders in the Vapi Dashboard are excited to combine and customize model configurations, but without guidance, it's hard to know which combinations actually win. And when your use case or goal changes, the best configuration changes with it. Vapi is model-agnostic: assemble an agent by choosing your own transcriber, LLM, and voice from an ever-expanding catalog of providers and models. That configurability is one of the reasons teams choose Vapi, but while the catalog grows, the range of choices can slow down decisions. New builders don't want to become experts in transcriber word error rates or TTS latency. They just want a working agent. Even power users who want to compare models can struggle without data they can trust. Vapi Inc. is in a rare position to fix that. Builders have run over 1 billion calls on Vapi with use cases spanning appointment scheduling, patient intake, collections, driver dispatch, and dozens of other real workloads. Vapi Inc. see how models actually behave in production, not in a spec sheet, and that's the data its own engineers use to select the models inside each preset. Neutrality without guidance just shifts the burden onto the builder. Model Intelligence adds the guidance: a recommendation for every use case, grounded in real deployments, plus the data to go deeper when you want it. What is Vapi Model Intelligence? One bundle, two features. Model Intelligence is a bundle that includes two features solving the same problem from different directions. Model Presets. Model Presets recommend a model selection for you, tuned to a specific goal, whether that's cost, speed, or intelligence. Each preset is a curated configuration that bundles a best-in-class transcriber, an LLM, and a voice: * Balanced. Strong across virtually any use case. This is the new platform default for all new assistants. * High Intelligence. The most capable models, for complex or high-stakes tasks where accuracy is the priority. * Ultra Fast. Optimized for the lowest latency, for use cases where speed matters most. * Cost Saver. Optimized for per-minute cost, so high-volume agents don't break the bank. Pick the preset that matches your goal and ship, without worrying that you're leaving something on the table. You never have to open a dropdown. If you do edit any component, the assistant moves to a Customized state, so presets never lock you in. Presets are also designed to be improved over time. Because Vapi stores which preset an agent is on, Vapi Inc. can update the underlying models as better ones emerge and suggest the upgrade to everyone on that preset. Nothing changes without your confirmation, so agents already in production stay put. If you opt in, your models are updated, and your configuration improves without a total rebuild. Model performance metrics. For builders in the dashboard who want control, every model now carries the data to assess it: cost, latency, and a quality metric fit to the job. For transcribers, compare Word Error Rate (accuracy). For LLMs, compare Intelligence scores. And for voices, see its proprietary Humanness Index(TM) directly on the platform: a 0 to 100 score of how human a voice model sounds in real-life deployments, as evaluated by the humans who hear them. "Sounds natural in a demo clip" and "sounds natural across thousands of live calls" are different claims, and it's a metric Vapi Inc. will use to empower builders that no other platform can surface. Benchmarks appear in cards and dropdowns, so you can compare models side by side without leaving Vapi. And performance metrics are only useful if you can trust them, so here's how they're measured: Latency is measured on live Vapi calls, not vendor specs. Most performance metrics come from controlled tests: one request, a clean network, no concurrent load, no real conversation around it. Those numbers look fast on a slide and rarely survive contact with production. Its figures are P50 medians from real traffic, so they reflect how a model actually performs in deployment. One thing Vapi Inc. learned building this: a number that looks high on paper often feels natural in a real call, so use its numbers to compare models on equal footing, then test perceived latency yourself. It is important for users considering latency to look at model performance in real, live deployments. Cost metrics for the models reflect assumptions based on typical usage in real Vapi calls, but your actual spend may vary depending on factors such as call length, complexity, prompt size, caching rates, tool responses, and more. Quality metrics vary by model type but are pulled from industry benchmarks plus Vapi's own proprietary data, including the Humanness Index for voices, a metric no other platform can surface. The data is refreshed on a regular cadence, so you're comparing current scores and metrics. The same measurements inform how its engineers select the models inside each preset, so the defaults are chosen by data, not by habit. This data is collected from hundreds of thousands of live voice agent deployments and used to empower its builders to go even further. Who is Vapi Model Intelligence for? The non-technical PM building an appointment scheduler and selects Ultra Fast to get more meetings on the books, faster. She ships a low-latency agent without ever comparing transcribers or LLMs. The healthcare team. A care coordinator handling sensitive patient intake calls needs to navigate complex situations, so the team starts on High Intelligence. Later, they compare voices by Humanness Index(TM) to find the most natural option, rather than running call after call to hear the difference. The cost-conscious operator. A high-volume feedback survey is a repetitive, low-complexity workload. Cost Saver keeps per-minute costs down without a custom build. The team without time to chase model releases. Months from now, when better models are available in the Balanced preset, they'll receive a suggested upgrade. Their agent improves without anyone rebuilding it. Everyone else. Whether you want to start from a stronger baseline or make more informed decisions when you customize, Model Intelligence meets you where you are: better defaults out of the box, and better data when you're ready to go deeper. Get started. Model Intelligence, including Model Presets and updated performance metrics, is now live in your account. New assistants start on Balanced. Switch presets or hand-pick models anytime. Pick the right models for your use case, without the guesswork.

Mylstingo
Jul 10th, 2026
Voice AI startup Vapi hits 00M valuation after Winning Amazon Ring.

Voice AI startup Vapi hits 00M valuation after Winning Amazon Ring. Voice AI heats up: Vapi reaches unicorn status. The voice AI market has a new unicorn. Vapi, a startup building infrastructure for AI-powered voice agents, has reportedly reached a $500 million valuation after a fiercely competitive fundraising process that saw the company fend off over 40 rival bidders. The most notable customer win driving investor enthusiasm: Amazon's Ring division, which chose Vapi to power next-generation voice interactions across its smart home security platform. Vapi's core technology enables developers to build, deploy, and scale voice AI agents that sound remarkably natural. Unlike first-generation voice bots that relied on rigid script trees, Vapi's platform leverages the latest advances in large language models and neural text-to-speech to create conversational experiences that adapt in real time. The agents can handle interruptions, understand context across long exchanges, and even detect emotional cues in a caller's voice to adjust their tone accordingly. Discover more Machine Learning Computer Science Dictionaries & Encyclopedias Winning the Amazon Ring contract was a watershed moment for the company. Ring processes millions of customer interactions daily, spanning everything from package delivery confirmations to emergency alarm responses. Deploying Vapi's voice agents across this footprint represents one of the largest real-world tests of conversational AI at scale. Early metrics reportedly show a 40% reduction in call handling time and a measurable improvement in customer satisfaction scores compared to Ring's previous interactive voice response system. Discover more AI Tools, Chatbots & Virtual Assistants Data Management Language Resources RECOMMENDED READ The Coming Wave: AI, Power, and the Greatest Dilemma of Its Age Mustafa Suleyman The definitive book on where AI is heading - written by one of the field founders. The $500 million valuation reflects broader market excitement about voice AI as a category. With improvements in speech recognition accuracy, latency reduction in streaming models, and the rise of multimodal AI that can process voice alongside text and images, the technology has crossed a threshold where it is genuinely useful for business applications. Analysts project the global voice AI market will exceed $50 billion by 2028, up from approximately $15 billion in 2025. Vapi's approach differs from some competitors by focusing on the developer experience. The platform offers APIs and SDKs that abstract away the complexity of managing GPU infrastructure, model routing, and audio streaming. Developers can integrate voice capabilities into their applications with as few as a dozen lines of code, which has made Vapi particularly popular among fast-moving startups and mid-market companies that want voice AI without building a dedicated machine learning team. Discover more Text & Instant Messaging Company News The company's rapid ascent from seed stage to unicorn in under three years mirrors the trajectory of other AI infrastructure plays that have captured investor attention in 2026. As businesses across industries look to automate customer service, sales outreach, and internal operations, the demand for reliable, scalable voice AI infrastructure shows no signs of slowing. With fresh capital and a marquee customer in Amazon, Vapi is well-positioned to capture a significant share of this growing market. Ramo is the editorial voice of Mylistingo - an AI and technology news platform based in The Hague, Netherlands. Covering artificial intelligence, machine learning, robotics, and the future of technology, Ramo delivers accurate, accessible reporting for both general audiences and industry professionals. Every article is fact-checked and written to meet Mylistingo's strict no-fabrication editorial standards. Google has announced the 20 startups selected for its 2026 India Accelerator program, with a strong emphasis on artificial intelligence and machine learning, reflecting the maturation of India's... Apple is preparing a significant upgrade to its on-device AI capabilities that could allow future iPhones to run far more powerful machine learning models directly on the handset,...

Vapi
Jun 4th, 2026
Our response to the June 3, 2026 supply chain incident.

Its response to the June 3, 2026 supply chain incident. Team Vapi - Jun 04, 2026 On June 3, 2026, Vapi identified and contained a supply chain incident associated with the Miasma/Shai-Hulud worm that affected repositories in the Vapi GitHub organization. Vapi became aware of the issue via its internal telemetry as soon as the impacted npm packages were deployed, and was able to remove the malicious code, clean, validate, and resolve the incident within a 3-hour window. Based on its investigation, no customer data, customer credentials, Vapi secrets, or keys (beyond the initial compromised access token) were accessed or exfiltrated. Four malicious versions of @vapi-ai/server-sdk were published to npm, but based on its review of npm download data, those versions had zero downloads before they were removed. Vapi Inc. has also not identified evidence that the malicious code executed in its GitHub Actions CI/CD environment. At this time, no customer action is required. Vapi Inc. is sharing more details below about what happened, what Vapi Inc. found, what Vapi Inc. did in response, and what customers can review as an additional precaution. What happened. On June 3, 2026, between approximately 22:56 and 23:30 UTC, an unexpired access token belonging to a developer's personal GitHub account was used to push malicious changes across repositories that account had access to. This included some Vapi repositories. The attack modified repository branch tips and introduced malicious files designed to execute through common developer and CI tooling paths. The malicious changes included scripts and hooks targeting developer tools and package workflows, including npm-related execution path and AI coding assistant configurations. In a limited number of repositories, the compromised account had elevated access. In such repositories where access was allowed, the worm disabled branch protections, preventing them from preventing the push. During the incident, npm indicated that new versions of @vapi-ai/server-sdk had been published. The versions containing the worm were published at approximately 4:30 pm PT / 11:30 pm UTC on June 3, 2026. Vapi Inc. removed and rolled back the malicious npm versions by approximately 7:20 pm PT the same day. Vapi Inc. has no evidence that the malicious code executed through its CI/CD environment, and its platform has not been impacted. What Vapi Inc. found. Based on its investigation: * Vapi Inc. has not identified evidence that customer data was accessed or exfiltrated. * Vapi Inc. has not identified evidence that customer credentials were accessed or exfiltrated. * Vapi Inc. has not identified evidence that Vapi secrets or keys were breached (beyond the initial compromised developer access token). * The malicious @vapi-ai/server-sdk versions had zero downloads before they were removed. * Vapi Inc. has not identified malicious packages published to PyPI, RubyGems, NuGet, Maven, Go, or Packagist as part of this incident. What Vapi Inc. did. After identifying the incident, Vapi Inc. took the following actions: * Removed the malicious npm versions. * Revoked access for the affected GitHub account. * Cleaned identified affected repositories and branches. Vapi Inc. deleted worm artifact branches and verified that the malicious files were no longer present on remediated branches. * Audited GitHub users and applications. Vapi Inc. reviewed GitHub users, access patterns, and authorized applications. Vapi Inc. also deployed an updated, stricter access policy to reduce unnecessary elevated access. * Added additional repository protections. Vapi Inc. hardened branch protections for SDK default branches to block force pushes and branch deletion by default, while preserving required release workflows. * Began rotating Vapi secrets and keys. Although Vapi Inc. has not identified evidence that Vapi secrets or keys were breached, Vapi Inc. is rotating them as a precaution. Customer guidance. Based on what Vapi Inc. know today, no customer action is required. Because the malicious npm versions had zero downloads before removal, Vapi Inc. do not believe customer environments installed these versions from npm. As a precaution, customers may review package manifests, lockfiles, and internal package mirrors for the following versions: * @vapi-ai/[email protected] * @vapi-ai/[email protected] * @vapi-ai/[email protected] * @vapi-ai/[email protected] If any of these versions are present in your environment, remove them and install a current, known-good version of @vapi-ai/server-sdk. If one of these versions was installed or executed in an environment containing credentials, rotate credentials that may have been available in that environment. Vapi Inc. will update this guidance if necessary. Faq. Were customer data or customer credentials compromised? No. Vapi Inc. has not identified evidence that customer data or customer credentials were accessed or exfiltrated. Were Vapi secrets or keys breached? No. Vapi Inc. has not identified evidence that Vapi secrets or keys beyond one initially affected access token were breached. Vapi Inc. is rotating Vapi secrets and keys as a precaution. Were the malicious npm versions downloaded? No. Based on its review of npm download data, the malicious @vapi-ai/server-sdk versions had zero downloads before they were removed. Which npm versions were affected? The affected versions were: * @vapi-ai/[email protected] * @vapi-ai/[email protected] * @vapi-ai/[email protected] * @vapi-ai/[email protected] These versions have been removed or rolled back. Were other Vapi packages affected? Vapi Inc. has not identified malicious packages published to PyPI, RubyGems, NuGet, Maven, Go, or Packagist as part of this incident. The malicious package publishing activity Vapi Inc. identified was limited to the npm versions listed above. Did the malicious code execute in Vapi CI/CD? Vapi Inc. has not identified evidence that the malicious code executed through its CI/CD environment. Why did branch protection not prevent this? The compromised developer account had elevated access to some repositories. In repositories where that access allowed administrator or maintainer bypass, branch protections did not block the push. Vapi Inc. has since reviewed and hardened repository access policies, application access, and branch protection settings. Do customers need to rotate Vapi API keys? Based on its current findings, Vapi Inc. is not requiring customers to rotate Vapi API keys. Customers may choose to rotate keys according to their own security policies. Vapi Inc. will update this guidance if its investigation identifies any reason to rotate customer keys. Did this affect Vapi production services? No, the platform and production services were not impacted. To reiterate, Vapi Inc. did not identify evidence of a breach of customer data, customer credentials, Vapi secrets, or Vapi keys. What is Vapi doing to reduce the risk of this happening again? Vapi Inc. has audited GitHub users and applications, enforced an updated GitHub access policy, added additional protections on SDK default branches, removed malicious npm versions, cleaned identified affected repositories and branches, and begun rotating Vapi secrets and keys. VAPI works continuously to enhance its development, package publishing, and CI/CD controls, including where elevated access and bypass permissions are allowed. What about the StepSecurity report? On June 4, 2026, Vapi Inc. learned about an article from StepSecurity titled "Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp." This article references an event that is relevant to Vapi Inc., specifically mentioning Vapi. Vapi Inc. want to note that Vapi identified and resolved the issue internally and in real-time, even before being aware of this article.