Trust & Security
Last updated 25 July 2026.
SLATE VENTURES LTD t/a Volt26 (NZBN 9429053681034) 21F Gordon Rd, Wanaka 9305, New Zealand
This page is written for technical evaluators — CTOs, security leads, and IT reviewers assessing Volt26 for their organisation. We aim to be direct about what we do, how we protect your data, and where we are still maturing.
For questions not answered here: legal@volt26.ai
Data residency
Customer data at rest is stored in AWS ap-southeast-2 (Sydney, Australia). This is the Supabase-managed Postgres database that holds all application data including organisation records, project data, agent interactions, and user accounts.
Application delivery is via Vercel's global CDN. Static assets and server-side rendering may be handled by Vercel edge nodes globally; however, all persistent data writes and reads resolve to the Sydney database.
Sub-processor regions are listed in full at: /subprocessors
Sub-processors
We maintain a published list of all third-party services that process customer data on our behalf.
Full list: /subprocessors
Key sub-processors as of this disclosure:
| Service | Purpose | Data location |
|---|---|---|
| Supabase (on AWS ap-southeast-2) | Database, auth, storage | Sydney, AU |
| Anthropic | AI model inference | US (see AI data handling below) |
| Vercel | Application hosting, CDN | Global (static/edge only) |
| Resend | Transactional email | US |
| Stripe | Payment processing (card data stays with Stripe) | US |
| PostHog | Product analytics | US |
| Userback | In-app feedback (page metadata + console logs) | Australia |
We will notify customers of material changes to this list with at least 30 days' notice by email.
Encryption
| Layer | Approach |
|---|---|
| Data in transit | TLS 1.2 or higher on all connections (browser to Vercel, Vercel to Supabase, Supabase API calls) |
| Data at rest | Encrypted at rest via AWS/Supabase default encryption (AES-256) |
| Backups | Encrypted at rest; managed by Supabase |
| Payment card data | Not stored by Volt26 — Stripe handles all card data under their PCI DSS compliance programme |
Tenant isolation
Volt26 is a multi-tenant SaaS platform. Each customer organisation is isolated using PostgreSQL Row-Level Security (RLS) policies enforced at the database layer.
This means:
- Every database query is scoped to the authenticated user's organisation by default.
- An application-layer bug that bypasses RLS would still be blocked at the database layer.
- Organisation data cannot be accessed by another tenant through normal application paths.
Access control and admin auditability
Production database access is restricted to a database allow-list. Currently only the founding engineer has direct database access.
Impersonation: Platform administrators have a capability to impersonate a user account for support purposes. Every use of this capability is recorded to an append-only admin action log that cannot be modified or deleted by the operator. Customers may request a copy of the admin action log for their organisation by contacting legal@volt26.ai.
Staff access: We are in the process of implementing a formal least-privilege access review for staff (see "What we're still building" below).
AI data handling
Volt26 uses Anthropic Claude exclusively for all AI functionality, called directly via the Anthropic API — no AI broker, aggregator, or middleware.
| Topic | Position |
|---|---|
| Training on customer data | No. Anthropic does not train on API customer inputs or outputs. Volt26 does not use your data for model training. |
| Anthropic data retention | Standard: approximately 30 days (safety/abuse monitoring). We are actively applying for Zero Data Retention (ZDR) with Anthropic; will update this page when confirmed. |
| Data path | Your inputs go directly from Volt26 to Anthropic's API and back. No intermediate storage of raw prompts/outputs by Volt26 at this time (see gaps below). |
| Autonomous agent actions | None today. Agents currently generate text only and do not call external APIs, execute code, send communications, or take real-world actions. As agent actions are introduced, they are gated behind your authorisation by risk level — actions that affect external systems or are hard to reverse require your approval, or a category you have explicitly pre-authorised. |
| Safety screening | Input and output safety screening is applied to all agent interactions. |
See our full AI Use Disclosure at /ai-disclosure.
Availability
Self-serve plans (Starter and Founder): the platform is provided on a best-efforts basis. We target 99.5% monthly uptime and operate to it as an internal objective, but self-serve plans do not carry a contractual service credit.
Enterprise: a contractual 99.5% monthly uptime SLA, with service credits and support response targets, is available and set out in a Service Level Agreement forming part of your Order Form.
Platform status: We do not currently publish a public status page.
Privacy and legal framework
Volt26 operates under New Zealand law and complies with the Privacy Act 2020 (NZ).
For customers in other jurisdictions (including Australia and the EU), our data processing terms address applicable cross-border transfer requirements. Contact legal@volt26.ai to discuss your jurisdiction's requirements.
Privacy Officer: Samantha Rae Contact: privacy@volt26.ai
Full Privacy Policy: /privacy
What we're still building
We are committed to being transparent about where our security and compliance programme is still maturing. The following items are genuine work in progress — we do not claim them as complete.
| Item | Status |
|---|---|
| Formal least-privilege staff access controls and access review process | In progress |
| Prompt and retrieved-context logging for incident reconstruction | In progress — currently no persistent log of AI inputs/outputs for forensics |
| Self-serve data export | Not yet available; contact legal@volt26.ai to request an export |
| Deletion-on-termination flow | In progress — account deletion currently requires a manual request |
| Published data retention policy | In progress |
| SOC 2 Type II | Not yet started; planned as enterprise demand requires it |
We will update this page as each item is completed.
Responsible disclosure
If you discover a security vulnerability in the Volt26 platform, please report it to legal@volt26.ai with the subject line "Security Disclosure". We will acknowledge your report within 2 business days and work with you on a coordinated disclosure timeline.
We do not currently operate a formal bug bounty programme.
Contact
Security and compliance questions: legal@volt26.ai Privacy enquiries: privacy@volt26.ai Privacy Officer: Samantha Rae
Related documents: