Skip to main content
    Security & Compliance

    Security Policies & Practices

    Comprehensive documentation of Voltade's security framework, data protection practices, and compliance standards.

    Last revised: October 2025

    Asset Configuration Policy

    Standards and security configurations for all assets

    Cloud Security Configurations

    Hetzner Cloud Security (Envoy CRM compute, Singapore sin-dc1):
    • Talos Linux immutable OS on a hardened Kubernetes cluster (control plane, Postgres, and worker nodes)
    • Kubernetes NetworkPolicies and private networking isolate internal services
    • CloudNativePG with synchronous replication and encryption at rest (AES-256)
    • Public endpoints reachable only through Cloudflare; operator access via Cloudflare Zero Trust
    AWS Security (Volty database, backups, email; ap-southeast-1):
    • AWS Config enabled to track configuration changes with alerts for non-compliant changes
    • AWS Identity and Access Management (IAM) enforces least-privilege access for all roles
    • Multi-Factor Authentication (MFA) enabled for root and privileged accounts
    • Security groups whitelist only Cloudflare IPs, with Cloudflare WAF for DDoS and web application protection
    • S3 server-side encryption for backups and attachments; Aurora encryption at rest
    Cloudflare Security:
    • Cloudflare Access for secure, identity-based application access without VPN
    • Zero Trust features including mutual TLS authentication for internal applications
    • TLS 1.3 or higher enforced for all web traffic
    • Rate Limiting and DDoS protection for web applications

    Password Policies

    • Default passwords must be updated immediately during initial configuration
    • Minimum length of 12 characters with uppercase, lowercase, numbers, and special characters
    • Passwords generated and stored using secure password manager (1Password)

    Data Transmission Protocols

    • HTTP replaced with HTTPS on all web-based services
    • TLS termination enabled at the Cloudflare edge and cluster load balancers
    • Always Use HTTPS enforced across all services via Cloudflare
    • WPA2/WPA3 encryption required for all wireless communications

    Logging and Monitoring

    • AWS CloudWatch for logging metrics, events, and alarms
    • SigNoz and Grafana (OpenTelemetry) for application metrics, traces, and diagnostic logs
    • Cloudflare Logs for DNS queries, firewall events, and HTTP requests
    • Logs retained for minimum 365 days; critical logs retained for 2 years

    Backup & Recovery Policy

    Procedures for backing up business-critical systems

    Daily Automated Backups

    • Cloud hosting providers perform automated daily backups of essential data
    • Backups maintained for up to 7 days for quick recovery
    • Backups stored separately from servers in cloud-based file storage
    • Access restricted to Admin role only

    Annual Manual Backup

    • Annual manual backup of business-critical data
    • Stored on password-protected encrypted USB in separate office location
    • Non-business-critical data (Google Drive, Notion) backed up annually

    Backup Testing

    • Restoration process tested at least twice per year
    • Ensures backups are functional and capable of restoring data in timely manner
    • Role-based access control for backup management

    Cloud Shared Responsibility Model

    Cloud hosting providers (Hetzner, AWS, Cloudflare) maintain infrastructure availability including automatic backup services. Voltade ensures data backup, encryption, and security configurations are correctly applied.

    Asset Management Policy

    Managing assets, onboarding, and secure disposal

    Unauthorised & EOS Assets

    • All unauthorised or EOS assets identified, removed, and replaced with supported versions
    • Continued use of EOS assets requires risk assessment and written management approval
    • Enhanced security controls applied until replacement is possible

    New Asset Onboarding

    • All new hardware and software undergo authorization process
    • Written approvals required via email or Telegram from Management
    • Assets sourced only from official or trusted sources
    • Malware scans conducted on all new assets before deployment

    Secure Asset Disposal

    • Data Deletion: Hard disk encrypted before reformatting; disk overwritten to prevent recovery
    • Physical Destruction: Hard disks physically destroyed or shredded via certified services
    • Documentation: Secure disposal report maintained with method details and data erasure confirmation

    Regular Audits

    Quarterly audits conducted focusing on unauthorised/EOS asset management, secure disposal records, and compliance with internal and external cybersecurity policies.

    Data Retention & Deletion Policy

    Data governance and secure deletion practices

    Default Retention Periods

    Data TypeRetention Period
    Conversations (WhatsApp, email, chat)Indefinitely unless SME requests deletion or configures shorter period (12, 24, 36 months)
    Knowledge Base (PDFs, websites, SOPs)Until explicitly deleted or replaced by SME
    Audit Logs18 months

    AI Training Data

    Voltade does not fine-tune AI models with customer data. Customer inputs are used ephemerally at runtime via Retrieval-Augmented Generation (RAG). No customer content is stored by OpenAI or other model providers beyond transient processing windows, in accordance with their Data Processing Addendums (DPAs).

    Secure Data Deletion Process

    1. Data Identification: All customer data objects (conversations, files, logs) mapped using internal identifiers
    2. Secure Wiping: Data deleted using provider-native secure wipe mechanisms:
      • Hetzner and AWS: Block and object storage zeroed or cryptographically wiped
      • Cloudflare: Cache entries purged globally within minutes
    3. Backups: Aged out within 30 days; encrypted and inaccessible until expiry
    4. Confirmation: Written confirmation via email that data has been permanently removed

    Technical Standards

    • Deletion operations follow NIST SP 800-88r1 standards for media sanitisation
    • Storage encryption (AES-256 at rest) ensures expired data is inaccessible before overwrite
    • All deletion events logged and auditable for compliance

    Endpoint Protection Policy

    Anti-malware, firewall, and network security

    Anti-Malware Requirements

    • MacBooks: Built-in XProtect solution considered sufficient
    • Windows: Up-to-date antivirus required (Windows Defender, McAfee, etc.)
    • Servers: Hardened, minimal-footprint Linux (Talos) with no interactive shell; container images scanned before deploy
    • Real-time scanning and automatic daily updates enabled
    • Full-system scan conducted at least quarterly

    Firewall Configuration

    • Perimeter Firewall: Analyses and restricts unauthorised traffic using packet filters, DNS firewalls, and application-level gateways
    • Endpoint Firewalls: Windows Defender Firewall or equivalent must remain active
    • Firewall rules reviewed annually

    Trusted Networks

    • Corporate Wi-Fi networks configured and monitored by IT
    • Personal Wi-Fi secured with WPA2/WPA3 encryption
    • VPN required when working remotely on public networks
    • Automatic connections to unsecured networks disabled

    Session Security

    • All devices automatically lock after 15 minutes of inactivity
    • Database and admin portal sessions time out after 15 minutes
    • Session timeout policies reviewed annually

    Accounts Management Policy

    Access control and authentication procedures

    Access Request Process

    1. Employee submits written request specifying system, role, and dates
    2. Management reviews for validity and alignment with policies
    3. If approved, access granted and logged in Accounts Tracker
    4. Password changed to strong passphrase (12+ characters) via 1Password
    5. 2FA implemented for admin accounts (Google Authenticator or SMS OTP)

    Access Revocation

    • Access revoked when employee leaves, role changes, or access no longer needed
    • Revocation processed immediately upon approval
    • Dormant accounts (60+ days inactive) disabled or removed

    Failed Login Protection

    • After 10 failed login attempts, further attempts are throttled
    • Suspected account compromise triggers immediate password change
    • Access logs reviewed quarterly for unauthorised access

    Administrator Access

    Administrator accounts restricted to Management only, used solely for administrative functions such as organisation setup, member management, and billing.

    Data Protection Impact Assessment (DPIA)

    Privacy risk assessment and mitigation

    Compliance Framework

    • Singapore's Personal Data Protection Act (PDPA)
    • GDPR Article 35 (where relevant for EU-based customers)
    • CSA Cyber Essentials Mark
    • ISO/IEC 27001 control families

    Categories of Personal Data

    • Identifiers: Customer names, phone numbers, email addresses
    • Communications: Messages, attachments, contextual chat history
    • Transactions: Quotation requests, invoices, appointments
    • Staff Data: Names, contact info, internal notes

    Technical Safeguards

    • Encryption: TLS 1.2/1.3 in transit, AES-256 at rest
    • Access Controls: MFA, least-privilege roles, just-in-time access for admins
    • Audit Logging: Immutable logs with anomaly monitoring
    • Spam/Scam Protection: LLM-powered auto-labelling for suspicious content

    Sub-Processors with DPAs

    • Hetzner Cloud – Kubernetes compute for Envoy CRM, Singapore (ISO 27001)
    • Amazon Web Services (AWS) – Aurora, S3, and SES in Singapore (ap-southeast-1)
    • Cloudflare – CDN, WAF, DDoS protection, and Zero Trust access
    • Microsoft Azure – container registry and Entra ID sign-in only; no customer data
    • OpenAI – Large Language Model API
    • Signoz/Sentry – Observability and error monitoring
    • Windmill – Secure automation/orchestration

    Data Subject Rights

    Voltade supports PDPA/GDPR-equivalent rights including access to personal data, correction of inaccuracies, deletion/erasure upon request, and objection to processing. Requests processed within 30 days.

    AI Transparency & Ethical AI

    Explainability and human oversight

    Retrieval-Augmented Generation (RAG)

    Voltade employs RAG to constrain AI responses to your knowledge base, preventing hallucination by anchoring outputs in vetted sources. This ensures the AI can only answer questions based on information you've provided.

    Explainability Features

    • Every AI answer cites its knowledge base sources
    • Explanations simplified into plain business language for non-technical users
    • Confidence scores generated for extracted data (leads, invoices)
    • Advanced debug mode shows reasoning traces for developers
    • GPT-5 reasoning models explain decision pathways when queried

    Human-in-the-Loop Oversight

    • Low-confidence results trigger automatic escalation to human operators
    • AI leaves internal notes with summary, reasoning, and confidence score
    • SMEs can configure escalation thresholds (e.g., "Always escalate financial data")
    • All corrections and overrides logged for accountability

    Bias Detection & Mitigation

    • Controlled Scope: RAG constrains responses to SME's own knowledge base, reducing exposure to global biases
    • Source Transparency: Citations allow SMEs to verify response basis
    • Continuous Feedback: Correction patterns monitored to detect bias
    • Lab Testing: Synthetic conversations surface unfair generalisations

    Region-Specific Threat Awareness

    AI auto-labelling protects SMEs against local threats:

    • Phishing & impersonation detection
    • Invoice fraud & business email compromise (BEC) flagging
    • Fake promotions & package scam identification
    • Multilingual evaluation (English, Mandarin, Malay, Tamil, Singlish)
    • Integration with CSA advisories and ScamShield reporting

    Security Questions?

    For security-related inquiries, data protection requests, or to report vulnerabilities, contact our security team.