Legal

Security

Security is foundational to VoltLayer. Our customers trust us with sensitive operational data — project drawings, change orders, financial estimates, crew schedules, and integration credentials for mission-critical platforms.

Last Updated: July 19, 2026

Our Security Principles

Tenant Isolation

Your data is never commingled with another customer's data. Each organization operates within a fully isolated environment. AI agents trained on your workflows, pricing logic, and approval chains have no access to any other customer's information, and vice versa.

Customer-Controlled Keys

Where encryption key management is offered, customers hold the keys. VoltLayer infrastructure cannot decrypt your data without your authorization. This means that even in the event of a breach of our systems, your data remains protected.

Human-in-the-Loop

Our platform is architecturally designed so that AI agents cannot take consequential external actions — sending a committed price, filing a report, executing a contract — without explicit human approval. Automation at VoltLayer is always accountable automation.

Infrastructure Security

Cloud Infrastructure

VoltLayer is hosted on enterprise-grade cloud infrastructure with SOC 2 Type II certification. Our infrastructure is deployed across multiple availability zones to ensure high availability and resilience against regional failures.

Encryption

All data transmitted between your browser or connected tools and VoltLayer's servers is encrypted using TLS 1.2 or higher. Data at rest — including Customer Data, integration credentials, and AI model configurations — is encrypted using AES-256. Integration credentials (OAuth tokens, API keys) are stored in an encrypted secrets vault and are never exposed in plaintext, even to VoltLayer engineers.

Network Security

VoltLayer's production environment is protected by a multi-layered network security architecture, including:

  • Web application firewall (WAF) with rules tuned for construction and SaaS attack patterns
  • DDoS mitigation at the network edge
  • Private VPC with strict ingress/egress controls
  • Intrusion detection and anomaly monitoring
  • Regular penetration testing by independent third-party security firms

Access Controls

Access to production systems is restricted to a small number of authorized VoltLayer engineers. All production access requires multi-factor authentication (MFA), is logged, and is subject to regular access reviews. Privileged access follows the principle of least privilege — engineers are granted only the minimum permissions required to perform their role.

Application Security

Secure Development Lifecycle

Security is integrated into every stage of our software development process. Our engineering team follows secure coding practices aligned with OWASP guidelines. All code changes undergo peer review, and automated security scanning is performed on every pull request to detect common vulnerabilities (SQL injection, XSS, CSRF, etc.) before they reach production.

Dependency Management

We continuously monitor our software dependencies for known vulnerabilities using automated tooling. Critical security patches are applied within 24 hours of disclosure; non-critical patches are addressed within our standard release cycle.

Authentication and Session Management

ControlDetails
Multi-factor authentication (MFA)Available and strongly recommended for all users
Single sign-on (SSO)SAML 2.0 and OIDC supported on Business and Enterprise plans
Session expirationIdle sessions expire after a configurable period
Password policyMinimum 12 characters, complexity requirements enforced
Credential breach detectionPasswords checked against known breach databases at login

Role-Based Access Control (RBAC)

Within your organization's VoltLayer account, administrators can assign granular permissions to users. Access to specific projects, integrations, AI workflows, and approval queues can be scoped to individual roles. All permission changes are logged and auditable.

Data Handling and Privacy

Data Isolation

Each customer's data resides in a logically isolated environment. Database queries, AI model training, and workflow execution are scoped to your tenant and cannot access another customer's data.

AI Model Training

VoltLayer's AI agents are trained on your organization's specific data — your workflows, your pricing logic, your approval chains. This training data is never used to improve models that serve other customers, and it is never shared with third parties.

Third-Party Integrations

When you connect VoltLayer to third-party platforms (Procore, QuickBooks, Bluebeam, Gmail, Outlook, etc.), we request only the OAuth scopes necessary to perform the workflows you have configured. You can review and revoke integration permissions at any time from your account settings. VoltLayer does not store third-party platform credentials beyond what is required for active integrations.

Data Retention and Deletion

Customer Data is retained for the duration of your subscription. Upon account termination, data is deleted within 90 days in accordance with our Privacy Policy. Customers may request earlier deletion by contacting admin@voltlayer.ai. Deletion is permanent and irreversible.

Organizational Security

Employee Security

All VoltLayer employees undergo background checks prior to hire. Employees with access to customer data or production systems complete security awareness training at onboarding and annually thereafter. Access to customer data is granted on a need-to-know basis and is reviewed quarterly.

Vendor Management

Third-party vendors who process customer data on our behalf are subject to security review and are required to maintain security standards consistent with our own. We maintain a current inventory of sub-processors and update our Privacy Policy when sub-processors change.

Incident Response

VoltLayer maintains a documented incident response plan. In the event of a confirmed security incident affecting customer data, we will notify affected customers within 72 hours of becoming aware of the incident, consistent with applicable legal requirements. Notifications will include a description of the incident, the data affected, and the steps we are taking to remediate the issue.

Compliance and Certifications

FrameworkStatus
SOC 2 Type IIIn progress — target Q4 2026
GDPRCompliant — DPA available upon request
CCPACompliant
NIST Cybersecurity FrameworkAligned

We will update this page as certifications are achieved. Customers on Enterprise plans may request our SOC 2 report under NDA by contacting admin@voltlayer.ai.

Responsible Disclosure

VoltLayer welcomes reports from security researchers and the broader community. If you believe you have discovered a security vulnerability in our platform, please report it to us at admin@voltlayer.ai before disclosing it publicly. We ask that you:

  • Provide sufficient detail to reproduce the issue.
  • Allow us a reasonable period (typically 90 days) to investigate and remediate before public disclosure.
  • Avoid accessing, modifying, or deleting customer data beyond what is necessary to demonstrate the vulnerability.

We commit to acknowledging your report within 48 hours, keeping you informed of our progress, and, where appropriate, publicly crediting your contribution.

Questions and Contact

For security-related questions, vulnerability reports, or to request our security documentation, please contact:

VoltLayer Security Team

Email: admin@voltlayer.ai

Privacy inquiries: admin@voltlayer.ai

General: admin@voltlayer.ai

💬 Chat with Volter