Comprehensive documentation of Voltade's security framework, data protection practices, and compliance standards.
Last updated: 25 August 2026
Standards and security configurations for all assets
Procedures for backing up business-critical systems
Cloud hosting providers (Hetzner, AWS, Cloudflare) maintain infrastructure availability including automatic backup services. Voltade ensures data backup, encryption, and security configurations are correctly applied.
Managing assets, onboarding, and secure disposal
Quarterly audits conducted focusing on unauthorised/EOS asset management, secure disposal records, and compliance with internal and external cybersecurity policies.
Data governance and secure deletion practices
| Data Type | Retention Period |
|---|---|
| Conversations (WhatsApp, email, chat) | Life of the conversation, unless deletion is requested |
| Knowledge Base (PDFs, websites, SOPs) | Until explicitly deleted or replaced by SME |
| Audit Logs | 18 months |
Voltade does not fine-tune AI models with customer data. Customer inputs are used ephemerally at runtime via Retrieval-Augmented Generation (RAG). Zero data retention is enforced on the model gateway, which restricts traffic to an allowlist of permitted provider hosts and prefers per-organisation keys over shared ones.
Anti-malware, firewall, and network security
Access control and authentication procedures
Administrator accounts restricted to Management only, used solely for administrative functions such as organisation setup, member management, and billing.
Privacy risk assessment and mitigation
Voltade supports PDPA/GDPR-equivalent rights including access to personal data, correction of inaccuracies, deletion/erasure upon request, and objection to processing. Requests processed within 30 days.
Explainability and human oversight
Voltade employs RAG to constrain AI responses to your knowledge base, preventing hallucination by anchoring outputs in vetted sources. This ensures the AI can only answer questions based on information you've provided.
AI auto-labelling protects SMEs against local threats:
How updates are tested, deployed, and communicated
Critical and important updates, including security patches, are implemented within 48 hours across operating systems, application frameworks, databases and managed dependencies.
No update is promoted to production until it has passed compatibility testing in a staging environment and cleared the automated verification gate:
Voltade is delivered as a hosted service — customers install, host and patch no Voltade software component, and carry no patch-implementation obligation. Updates are communicated as follows:
For security-related inquiries, data protection requests, or to report vulnerabilities, contact our security team.