Skip to main content
    Security & Compliance

    Trust Centre

    Transparency in security, compliance, and data protection. View our certifications, security controls, and subprocessor information.

    Last updated: February 2026

    5
    Certifications
    44+
    Security Controls
    9.7/10
    Pentest Score
    99.9%
    Uptime SLA

    Compliance & Certifications

    Industry certifications and compliance standards

    CASA

    CASA Tier 2 (App Defense Alliance)

    Cloud Application Security Assessment certified Tier 2 (Lab Tested - Lab Verified) under the App Defense Alliance, independently assessed by TAC Security against the OWASP ASVS standard. Valid through 15 April 2027.

    Verified: April 2026
    Cyber Essentials Mark

    Cyber Essentials Mark

    Singapore CSA Cyber Essentials certification demonstrating baseline cybersecurity hygiene and practices.

    Verified: 2025
    PDPA

    PDPA Compliance

    Full compliance with Singapore Personal Data Protection Act requirements for data collection, use, and disclosure.

    Verified: Ongoing
    Meta Business Partner

    Meta Business Partner

    Verified Meta Business Partner with WhatsApp Business API integration expertise.

    Verified: 2025
    IMDA SMEs Go Digital Pre-Approved Solution

    IMDA SMEs Go Digital Pre-Approved Solution

    SMEs are eligible for up to 50% Productivity Solutions Grant (PSG) support for the adoption of Voltade AI solutions, a Pre-Approved Solution under the IMDA SMEs Go Digital programme.

    Verified: 2025

    Security Documents

    Reports, assessments, and compliance documentation

    CASA Tier 2 Certificate

    Latest

    App Defense Alliance Cloud Application Security Assessment (CASA) Tier 2 Statement of Validation, independently lab-tested and verified by TAC Security. Valid through 15 April 2027.

    14 Apr 2026

    CASA Security Scan Report

    On Request

    Full CASA application security scan report (ESOF AppSec / ADA CASA) covering web application, API, and infrastructure security testing against the OWASP ASVS standard. Available for enterprise evaluation under NDA.

    Penetration Test Report

    CASA TAC Security assessment report covering web application, API, and infrastructure security testing. Score: 9.7/10. All identified vulnerabilities have been patched.

    16 May 2025

    Data Processing Agreement (DPA)

    On Request

    Standard contractual clauses for data processing, GDPR and PDPA compliant terms for enterprise customers.

    Security Questionnaire Response

    On Request

    Pre-filled security questionnaire based on SIG Lite and CAIQ formats. Available for enterprise evaluation.

    SOC 2 Type II Report

    In Progress

    Service Organization Control audit report covering security, availability, and confidentiality.

    Security Controls

    43 of 44 controls implemented

    Infrastructure Security

    TLS 1.3 encryption for all traffic
    Implemented
    High-availability cluster (3× control plane, synchronous Postgres replication)
    Implemented
    Cloudflare WAF & DDoS protection
    Implemented
    Kubernetes orchestration
    Implemented
    Network isolation & segmentation
    Implemented
    Cross-region redundancy
    Planned
    Automated infrastructure scaling
    Implemented

    Data Protection

    AES-256 encryption at rest
    Implemented
    TLS encryption in transit
    Implemented
    Row-level security (RLS)
    Implemented
    Per-tenant data isolation
    Implemented
    GDPR-ready data handling
    Implemented
    PDPA compliance
    Implemented
    Automated data backup
    Implemented
    Point-in-time recovery
    Implemented

    Access Control

    SSO via ZITADEL
    Implemented
    Multi-factor authentication (MFA)
    Implemented
    Role-based access control (RBAC)
    Implemented
    Comprehensive audit logging
    Implemented
    Break-glass emergency procedures
    Implemented
    Session management & timeout
    Implemented
    IP allowlisting (enterprise)
    Implemented

    Application Security

    CASA Tier 2 certified
    Implemented
    Annual penetration testing
    Implemented
    Continuous vulnerability scanning
    Implemented
    Bot mitigation
    Implemented
    Anti-DDoS protection
    Implemented
    Secure SDLC practices
    Implemented
    Dependency vulnerability scanning
    Implemented
    Code review requirements
    Implemented

    Incident Response

    24/7 monitoring & alerting
    Implemented
    Documented incident response plan
    Implemented
    Disaster recovery tested
    Implemented
    Status page available
    Implemented
    Post-incident reviews
    Implemented
    Customer notification procedures
    Implemented
    Incident classification system
    Implemented

    AI Governance

    RAG-based explainability
    Implemented
    Human-in-the-loop controls
    Implemented
    No customer data for model training
    Implemented
    Complete AI audit trails
    Implemented
    Bias monitoring & mitigation
    Implemented
    Model versioning & rollback
    Implemented
    AI ethics guidelines
    Implemented

    Security Policies

    Comprehensive documentation of our security practices

    Governance & Ethics Policies

    Business conduct, data protection, and responsible business commitments

    Subprocessors

    Third-party service providers we work with

    ProviderPurposeCertificationsDocumentation

    Hetzner Cloud

    Kubernetes Compute (Envoy CRM)

    Kubernetes compute for Envoy CRM, hosted in Hetzner's Singapore data centre (sin-dc1).

    ISO 27001
    GDPR
    View
    Amazon Web Services (AWS)

    Amazon Web Services (AWS)

    Database, Backups & Email

    Aurora Postgres (Volty), S3 for backups and attachments, and SES for transactional email, all in the Singapore region (ap-southeast-1).

    SOC 2
    ISO 27001
    GDPR
    HIPAA
    View
    Cloudflare

    Cloudflare

    CDN, WAF & DDoS Protection

    Content delivery network, web application firewall, DDoS mitigation, and Zero Trust operator access.

    SOC 2
    ISO 27001
    PCI DSS
    View
    Microsoft Azure

    Microsoft Azure

    Container Registry & Sign-in

    Internal container registry for image distribution and Microsoft Entra ID sign-in. No customer data is stored or processed on Azure.

    SOC 2
    ISO 27001
    GDPR
    HIPAA
    View

    Anthropic

    Large Language Model API

    Claude language models for agent reasoning. API access only; no training on customer data.

    SOC 2
    ISO 27001
    View
    OpenAI

    OpenAI

    Large Language Model API

    GPT language models for selected tasks. API data excluded from training by default.

    SOC 2
    View

    Google (Gemini)

    Large Language Model API

    Gemini language models for selected tasks. Paid API data not used to train models.

    SOC 2
    ISO 27001
    View
    SigNoz / Sentry

    SigNoz / Sentry

    Observability & Monitoring

    Application performance monitoring, error tracking, and observability.

    SOC 2
    View
    Windmill

    Windmill

    Secure Automation

    Self-hosted workflow automation and orchestration platform.

    Self-hosted
    View

    Last updated: July 2026. For questions about our subprocessors, contact [email protected]

    Contact Our Security Team

    Have questions about our security practices? Need a custom DPA or security questionnaire? Our team is here to help.