Trust & Security

Last updated 25 July 2026.

SLATE VENTURES LTD t/a Volt26 (NZBN 9429053681034) 21F Gordon Rd, Wanaka 9305, New Zealand

This page is written for technical evaluators — CTOs, security leads, and IT reviewers assessing Volt26 for their organisation. We aim to be direct about what we do, how we protect your data, and where we are still maturing.

For questions not answered here: legal@volt26.ai


Data residency

Customer data at rest is stored in AWS ap-southeast-2 (Sydney, Australia). This is the Supabase-managed Postgres database that holds all application data including organisation records, project data, agent interactions, and user accounts.

Application delivery is via Vercel's global CDN. Static assets and server-side rendering may be handled by Vercel edge nodes globally; however, all persistent data writes and reads resolve to the Sydney database.

Sub-processor regions are listed in full at: /subprocessors


Sub-processors

We maintain a published list of all third-party services that process customer data on our behalf.

Full list: /subprocessors

Key sub-processors as of this disclosure:

ServicePurposeData location
Supabase (on AWS ap-southeast-2)Database, auth, storageSydney, AU
AnthropicAI model inferenceUS (see AI data handling below)
VercelApplication hosting, CDNGlobal (static/edge only)
ResendTransactional emailUS
StripePayment processing (card data stays with Stripe)US
PostHogProduct analyticsUS
UserbackIn-app feedback (page metadata + console logs)Australia

We will notify customers of material changes to this list with at least 30 days' notice by email.


Encryption

LayerApproach
Data in transitTLS 1.2 or higher on all connections (browser to Vercel, Vercel to Supabase, Supabase API calls)
Data at restEncrypted at rest via AWS/Supabase default encryption (AES-256)
BackupsEncrypted at rest; managed by Supabase
Payment card dataNot stored by Volt26 — Stripe handles all card data under their PCI DSS compliance programme

Tenant isolation

Volt26 is a multi-tenant SaaS platform. Each customer organisation is isolated using PostgreSQL Row-Level Security (RLS) policies enforced at the database layer.

This means:

  • Every database query is scoped to the authenticated user's organisation by default.
  • An application-layer bug that bypasses RLS would still be blocked at the database layer.
  • Organisation data cannot be accessed by another tenant through normal application paths.

Access control and admin auditability

Production database access is restricted to a database allow-list. Currently only the founding engineer has direct database access.

Impersonation: Platform administrators have a capability to impersonate a user account for support purposes. Every use of this capability is recorded to an append-only admin action log that cannot be modified or deleted by the operator. Customers may request a copy of the admin action log for their organisation by contacting legal@volt26.ai.

Staff access: We are in the process of implementing a formal least-privilege access review for staff (see "What we're still building" below).


AI data handling

Volt26 uses Anthropic Claude exclusively for all AI functionality, called directly via the Anthropic API — no AI broker, aggregator, or middleware.

TopicPosition
Training on customer dataNo. Anthropic does not train on API customer inputs or outputs. Volt26 does not use your data for model training.
Anthropic data retentionStandard: approximately 30 days (safety/abuse monitoring). We are actively applying for Zero Data Retention (ZDR) with Anthropic; will update this page when confirmed.
Data pathYour inputs go directly from Volt26 to Anthropic's API and back. No intermediate storage of raw prompts/outputs by Volt26 at this time (see gaps below).
Autonomous agent actionsNone today. Agents currently generate text only and do not call external APIs, execute code, send communications, or take real-world actions. As agent actions are introduced, they are gated behind your authorisation by risk level — actions that affect external systems or are hard to reverse require your approval, or a category you have explicitly pre-authorised.
Safety screeningInput and output safety screening is applied to all agent interactions.

See our full AI Use Disclosure at /ai-disclosure.


Availability

Self-serve plans (Starter and Founder): the platform is provided on a best-efforts basis. We target 99.5% monthly uptime and operate to it as an internal objective, but self-serve plans do not carry a contractual service credit.

Enterprise: a contractual 99.5% monthly uptime SLA, with service credits and support response targets, is available and set out in a Service Level Agreement forming part of your Order Form.

Platform status: We do not currently publish a public status page.


Privacy and legal framework

Volt26 operates under New Zealand law and complies with the Privacy Act 2020 (NZ).

For customers in other jurisdictions (including Australia and the EU), our data processing terms address applicable cross-border transfer requirements. Contact legal@volt26.ai to discuss your jurisdiction's requirements.

Privacy Officer: Samantha Rae Contact: privacy@volt26.ai

Full Privacy Policy: /privacy


What we're still building

We are committed to being transparent about where our security and compliance programme is still maturing. The following items are genuine work in progress — we do not claim them as complete.

ItemStatus
Formal least-privilege staff access controls and access review processIn progress
Prompt and retrieved-context logging for incident reconstructionIn progress — currently no persistent log of AI inputs/outputs for forensics
Self-serve data exportNot yet available; contact legal@volt26.ai to request an export
Deletion-on-termination flowIn progress — account deletion currently requires a manual request
Published data retention policyIn progress
SOC 2 Type IINot yet started; planned as enterprise demand requires it

We will update this page as each item is completed.


Responsible disclosure

If you discover a security vulnerability in the Volt26 platform, please report it to legal@volt26.ai with the subject line "Security Disclosure". We will acknowledge your report within 2 business days and work with you on a coordinated disclosure timeline.

We do not currently operate a formal bug bounty programme.


Contact

Security and compliance questions: legal@volt26.ai Privacy enquiries: privacy@volt26.ai Privacy Officer: Samantha Rae

Related documents: