# Trust Centre

> The Voltade Trust Centre holds our security certifications, compliance reports, penetration test results and subprocessors. CASA Tier 2 certified.

Transparency in security, compliance, and data protection. View our certifications, security controls, and subprocessor information.

Updated 25 Aug 2026

5

Certifications

44+

Security Controls

9.7/10

Pentest Score

99.5%

Uptime SLA

## Quick Navigation

### Certifications & evidence

- Compliance & Certifications CASA Tier 2, Cyber Essentials Mark, PDPA
- Security Documents Penetration test report, DPA, questionnaire response
- Independently Verified Controls Seven controls checked against production, 19 Aug 2026
- PSG Pre-Approved Solution Our IMDA SMEs Go Digital listing

### How the platform works

- Security Controls 45 controls across six categories
- Security Principles Architecture, availability, backups and recovery
- Data Residency & AI Infrastructure Where data is stored and which models run on it
- How the Platform Handles Your Data Tenant isolation, gated actions, deletion
- Subprocessors Nine providers and what each one does

### Policies & governance

- Security Policies Retention, backup, endpoint, DPIA, AI transparency
- Personal Data Protection Policy PDPA obligations, safeguards, breach response
- Anti-Bribery & Corruption Zero tolerance, gifts, sanctions, anti-money-laundering
- Whistleblowing Confidential reporting channels, no retaliation
- ESG & Responsible Business Environment, labour standards, supply chain

### Answers & contact

- Security FAQ Eighteen vendor questionnaire answers, in full
- Contact Our Security Team team@voltade.co

## Compliance & Certifications

Industry certifications and compliance standards

CASA

### CASA Tier 2 (App Defense Alliance)

Cloud Application Security Assessment certified Tier 2 (Lab Tested - Lab Verified) under the App Defense Alliance, independently assessed by TAC Security against the OWASP ASVS standard. Valid through 15 April 2027.

Verified: April 2026

### Cyber Essentials Mark

CSA Cybersecurity Certification - Cyber Essentials (2025) for ICT Vendors, certified by ISOCert (certificate CEM-2024-097). Covers the production and development environment of the ICT vendor for the service. Valid through 15 October 2028.

Verified: August 2026

PDPA

### PDPA Compliance

Full compliance with Singapore Personal Data Protection Act requirements for data collection, use, and disclosure.

Verified: Ongoing

### Meta Business Partner

Verified Meta Business Partner with WhatsApp Business API integration expertise.

Verified: 2025

### IMDA SMEs Go Digital Pre-Approved Solution

SMEs are eligible for up to 50% Productivity Solutions Grant (PSG) support for the adoption of Voltade AI solutions, a Pre-Approved Solution under the IMDA SMEs Go Digital programme.

Verified: 2025

## Security Documents

Reports, assessments, and compliance documentation

### CASA Tier 2 Certificate

Latest

App Defense Alliance Cloud Application Security Assessment (CASA) Tier 2 Statement of Validation, independently lab-tested and verified by TAC Security. Valid through 15 April 2027.

14 Apr 2026

Download PDF

### Cyber Essentials Certificate

Latest

CSA Cybersecurity Certification - Cyber Essentials (2025) for ICT Vendors, certificate CEM-2024-097 issued by ISOCert. Covers the production and development environment of the ICT vendor for the service. Valid through 15 October 2028.

21 Aug 2026

Download PDF

### CASA Security Scan Report

On Request

Full CASA application security scan report (ESOF AppSec / ADA CASA) covering web application, API, and infrastructure security testing against the OWASP ASVS standard. Available for enterprise evaluation under NDA.

Request

### Penetration Test Report

CASA TAC Security assessment report covering web application, API, and infrastructure security testing. Score: 9.7/10. All identified vulnerabilities have been patched.

16 May 2025

Download PDF

### Data Processing Agreement (DPA)

On Request

Standard contractual clauses for data processing, GDPR and PDPA compliant terms for enterprise customers.

Request

### Security Questionnaire Response

On Request

Pre-filled security questionnaire based on SIG Lite and CAIQ formats. Available for enterprise evaluation.

Request

### SOC 2 Type II Report

In Progress

Service Organization Control audit report covering security, availability, and confidentiality.

## Security Controls

44 of 45 controls implemented

### Infrastructure Security

TLS 1.3 encryption for all traffic

Implemented

High-availability cluster (3× control plane, synchronous Postgres replication)

Implemented

Cloudflare WAF & DDoS protection

Implemented

Kubernetes orchestration

Implemented

Network isolation & segmentation

Implemented

Cross-region redundancy

Planned

Automated infrastructure scaling

Implemented

### Data Protection

AES-256 encryption at rest

Implemented

TLS encryption in transit

Implemented

Row-level security (RLS)

Implemented

Per-tenant data isolation

Implemented

GDPR-ready data handling

Implemented

PDPA compliance

Implemented

Automated data backup

Implemented

Point-in-time recovery

Implemented

### Access Control

SSO via ZITADEL

Implemented

Multi-factor authentication (MFA)

Implemented

Role-based access control (RBAC)

Implemented

Comprehensive audit logging

Implemented

Break-glass emergency procedures

Implemented

Session management & timeout

Implemented

IP allowlisting (enterprise)

Implemented

### Application Security

CASA Tier 2 certified

Implemented

Annual penetration testing

Implemented

Continuous vulnerability scanning

Implemented

Bot mitigation

Implemented

Anti-DDoS protection

Implemented

Secure SDLC practices

Implemented

Dependency vulnerability scanning

Implemented

Code review requirements

Implemented

### Incident Response

24/7 monitoring & alerting

Implemented

GuardDuty threat detection

Implemented

Documented incident response plan

Implemented

Disaster recovery tested

Implemented

Status page available

Implemented

Post-incident reviews

Implemented

Customer notification procedures

Implemented

Incident classification system

Implemented

### AI Governance

RAG-based explainability

Implemented

Human-in-the-loop controls

Implemented

No customer data for model training

Implemented

Complete AI audit trails

Implemented

Bias monitoring & mitigation

Implemented

Model versioning & rollback

Implemented

AI ethics guidelines

Implemented

## Security Policies

Comprehensive documentation of our security practices

Asset Configuration Policy · Standards and security configurations for cloud and on-premise assets · Backup & Recovery Policy · Data backup procedures, retention periods, and disaster recovery · Asset Management Policy · Asset lifecycle, onboarding, and secure disposal procedures · Data Retention & Deletion · Data governance, retention periods, and secure deletion practices · Endpoint Protection Policy · Device security, antivirus, and endpoint management · Accounts Management Policy · User provisioning, access control, and authentication · Data Protection (DPIA) · Data protection impact assessments and privacy controls · AI Transparency & Ethics · AI governance, explainability, and ethical guidelines

View all security policies

### Governance & Ethics Policies

Business conduct, data protection, and responsible business commitments

Anti-Bribery & Corruption Policy · Zero tolerance for bribery, AML/CFT controls, and sanctions compliance · Whistleblowing Policy · Confidential, anonymous reporting for employees and third parties · Personal Data Protection Policy · PDPA governance: DPO, safeguards, transfers, breach response, retention · ESG & Responsible Business · Environment, labour standards, human rights, and supply chain responsibility · Data Residency & AI Infrastructure · Storage locations, AI models used, safeguards, and third parties

## Subprocessors

Third-party service providers we work with

| Provider | Purpose | Certifications | Documentation |
| --- | --- | --- | --- |
| Hetzner Cloud · Kubernetes Compute (Voltade) | Kubernetes compute for Voltade, hosted in Hetzner's Singapore data centre (sin-dc1). | ISO 27001 · GDPR | View |
| Amazon Web Services (AWS) · Database, Backups & Email | Aurora Postgres (Volty), S3 for backups and attachments, and SES for transactional email, all in the Singapore region (ap-southeast-1). | SOC 2 · ISO 27001 · GDPR · HIPAA | View |
| Cloudflare · CDN, WAF & DDoS Protection | Content delivery network, web application firewall, DDoS mitigation, and Zero Trust operator access. | SOC 2 · ISO 27001 · PCI DSS | View |
| Microsoft Azure · Container Registry & Sign-in | Internal container registry for image distribution and Microsoft Entra ID sign-in. No customer data is stored or processed on Azure. | SOC 2 · ISO 27001 · GDPR · HIPAA | View |
| Anthropic · Large Language Model API | Claude language models for agent reasoning. API access only; no training on customer data. | SOC 2 · ISO 27001 | View |
| OpenAI · Large Language Model API | GPT language models for selected tasks. API data excluded from training by default. | SOC 2 | View |
| Google (Gemini) · Large Language Model API | Gemini language models for selected tasks. Paid API data not used to train models. | SOC 2 · ISO 27001 | View |
| SigNoz / Sentry · Observability & Monitoring | Application performance monitoring, error tracking, and observability. | SOC 2 | View |
| Windmill · Secure Automation | Self-hosted workflow automation and orchestration platform. | Self-hosted | View |

Last updated: July 2026. For questions about our subprocessors, contact team@voltade.co

## Frequently Asked Questions

Voltade holds CASA TAC Security Tier 2 certification, Cyber Essentials Mark from CSA Singapore, and is PDPA compliant. We are also a Meta Business Partner and IMDA PSG pre-approved vendor.

Yes. All data is encrypted using AES-256 encryption at rest and TLS 1.3 encryption in transit. We implement row-level security and per-tenant data isolation. Encryption at rest was independently verified on 19 August 2026 across the production database, its automated snapshots, and object storage.

Our primary subprocessors include Hetzner Cloud (Singapore) for Envoy CRM compute, AWS (Singapore) for the Volty database, backups, and transactional email, Cloudflare for CDN and DDoS protection, Microsoft Azure as an internal container registry only, OpenAI for LLM API, and SigNoz for observability.

No. Voltade does not use customer data to train AI models. Customer inputs are processed ephemerally via Retrieval-Augmented Generation (RAG), and zero data retention is enforced on the model gateway, which restricts traffic to an allowlist of permitted provider hosts.

## Contact Our Security Team

Have questions about our security practices? Need a custom DPA or security questionnaire? Our team is here to help.

Contact Voltade Team · View Security FAQ

## Links

- [Independently Verified ControlsSeven controls checked against production, 19 Aug 2026](https://voltade.com/sg/security/security-principles#verified-controls)
- [PSG Pre-Approved SolutionOur IMDA SMEs Go Digital listing](https://voltade.com/sg/imda-accredited-ai-vendor-singapore)
- [Security PrinciplesArchitecture, availability, backups and recovery](https://voltade.com/sg/security/security-principles)
- [Data Residency & AI InfrastructureWhere data is stored and which models run on it](https://voltade.com/sg/security/data-residency-ai)
- [How the Platform Handles Your DataTenant isolation, gated actions, deletion](https://voltade.com/sg/security/data-residency-ai#platform)
- [Security PoliciesRetention, backup, endpoint, DPIA, AI transparency](https://voltade.com/sg/security/security-policies)
- [Personal Data Protection PolicyPDPA obligations, safeguards, breach response](https://voltade.com/sg/security/data-protection-policy)
- [Anti-Bribery & CorruptionZero tolerance, gifts, sanctions, anti-money-laundering](https://voltade.com/sg/security/anti-bribery-policy)
- [WhistleblowingConfidential reporting channels, no retaliation](https://voltade.com/sg/security/whistleblowing-policy)
- [ESG & Responsible BusinessEnvironment, labour standards, supply chain](https://voltade.com/sg/security/esg-statement)
- [Security FAQEighteen vendor questionnaire answers, in full](https://voltade.com/sg/security/security-faq)
- [https://voltade.com/documents/cyber-essentials-certificate-2026.pdf](https://voltade.com/documents/cyber-essentials-certificate-2026.pdf)
- [Download PDF](https://voltade.com/documents/casa-tier2-certificate-2026.pdf)
- [Download PDF](https://voltade.com/documents/pentest-report-2025.pdf)
- [Asset Configuration PolicyStandards and security configurations for cloud and on-premise assets](https://voltade.com/sg/security/security-policies#asset-configuration)
- [Backup & Recovery PolicyData backup procedures, retention periods, and disaster recovery](https://voltade.com/sg/security/security-policies#backup-policy)
- [Asset Management PolicyAsset lifecycle, onboarding, and secure disposal procedures](https://voltade.com/sg/security/security-policies#asset-management)
- [Data Retention & DeletionData governance, retention periods, and secure deletion practices](https://voltade.com/sg/security/security-policies#data-retention)
- [Endpoint Protection PolicyDevice security, antivirus, and endpoint management](https://voltade.com/sg/security/security-policies#endpoint-protection)
- [Accounts Management PolicyUser provisioning, access control, and authentication](https://voltade.com/sg/security/security-policies#accounts-management)
- [Data Protection (DPIA)Data protection impact assessments and privacy controls](https://voltade.com/sg/security/security-policies#data-protection)
- [AI Transparency & EthicsAI governance, explainability, and ethical guidelines](https://voltade.com/sg/security/security-policies#ai-transparency)
