Legal
Security
Security is foundational to VoltLayer. Our customers trust us with sensitive operational data — project drawings, change orders, financial estimates, crew schedules, and integration credentials for mission-critical platforms.
Last Updated: July 19, 2026
Our Security Principles
Tenant Isolation
Your data is never commingled with another customer's data. Each organization operates within a fully isolated environment. AI agents trained on your workflows, pricing logic, and approval chains have no access to any other customer's information, and vice versa.
Customer-Controlled Keys
Where encryption key management is offered, customers hold the keys. VoltLayer infrastructure cannot decrypt your data without your authorization. This means that even in the event of a breach of our systems, your data remains protected.
Human-in-the-Loop
Our platform is architecturally designed so that AI agents cannot take consequential external actions — sending a committed price, filing a report, executing a contract — without explicit human approval. Automation at VoltLayer is always accountable automation.
Infrastructure Security
Cloud Infrastructure
VoltLayer is hosted on enterprise-grade cloud infrastructure with SOC 2 Type II certification. Our infrastructure is deployed across multiple availability zones to ensure high availability and resilience against regional failures.
Encryption
All data transmitted between your browser or connected tools and VoltLayer's servers is encrypted using TLS 1.2 or higher. Data at rest — including Customer Data, integration credentials, and AI model configurations — is encrypted using AES-256. Integration credentials (OAuth tokens, API keys) are stored in an encrypted secrets vault and are never exposed in plaintext, even to VoltLayer engineers.
Network Security
VoltLayer's production environment is protected by a multi-layered network security architecture, including:
- •Web application firewall (WAF) with rules tuned for construction and SaaS attack patterns
- •DDoS mitigation at the network edge
- •Private VPC with strict ingress/egress controls
- •Intrusion detection and anomaly monitoring
- •Regular penetration testing by independent third-party security firms
Access Controls
Access to production systems is restricted to a small number of authorized VoltLayer engineers. All production access requires multi-factor authentication (MFA), is logged, and is subject to regular access reviews. Privileged access follows the principle of least privilege — engineers are granted only the minimum permissions required to perform their role.
Application Security
Secure Development Lifecycle
Security is integrated into every stage of our software development process. Our engineering team follows secure coding practices aligned with OWASP guidelines. All code changes undergo peer review, and automated security scanning is performed on every pull request to detect common vulnerabilities (SQL injection, XSS, CSRF, etc.) before they reach production.
Dependency Management
We continuously monitor our software dependencies for known vulnerabilities using automated tooling. Critical security patches are applied within 24 hours of disclosure; non-critical patches are addressed within our standard release cycle.
Authentication and Session Management
Role-Based Access Control (RBAC)
Within your organization's VoltLayer account, administrators can assign granular permissions to users. Access to specific projects, integrations, AI workflows, and approval queues can be scoped to individual roles. All permission changes are logged and auditable.
Data Handling and Privacy
Data Isolation
Each customer's data resides in a logically isolated environment. Database queries, AI model training, and workflow execution are scoped to your tenant and cannot access another customer's data.
AI Model Training
VoltLayer's AI agents are trained on your organization's specific data — your workflows, your pricing logic, your approval chains. This training data is never used to improve models that serve other customers, and it is never shared with third parties.
Third-Party Integrations
When you connect VoltLayer to third-party platforms (Procore, QuickBooks, Bluebeam, Gmail, Outlook, etc.), we request only the OAuth scopes necessary to perform the workflows you have configured. You can review and revoke integration permissions at any time from your account settings. VoltLayer does not store third-party platform credentials beyond what is required for active integrations.
Data Retention and Deletion
Customer Data is retained for the duration of your subscription. Upon account termination, data is deleted within 90 days in accordance with our Privacy Policy. Customers may request earlier deletion by contacting admin@voltlayer.ai. Deletion is permanent and irreversible.
Organizational Security
Employee Security
All VoltLayer employees undergo background checks prior to hire. Employees with access to customer data or production systems complete security awareness training at onboarding and annually thereafter. Access to customer data is granted on a need-to-know basis and is reviewed quarterly.
Vendor Management
Third-party vendors who process customer data on our behalf are subject to security review and are required to maintain security standards consistent with our own. We maintain a current inventory of sub-processors and update our Privacy Policy when sub-processors change.
Incident Response
VoltLayer maintains a documented incident response plan. In the event of a confirmed security incident affecting customer data, we will notify affected customers within 72 hours of becoming aware of the incident, consistent with applicable legal requirements. Notifications will include a description of the incident, the data affected, and the steps we are taking to remediate the issue.
Compliance and Certifications
We will update this page as certifications are achieved. Customers on Enterprise plans may request our SOC 2 report under NDA by contacting admin@voltlayer.ai.
Responsible Disclosure
VoltLayer welcomes reports from security researchers and the broader community. If you believe you have discovered a security vulnerability in our platform, please report it to us at admin@voltlayer.ai before disclosing it publicly. We ask that you:
- •Provide sufficient detail to reproduce the issue.
- •Allow us a reasonable period (typically 90 days) to investigate and remediate before public disclosure.
- •Avoid accessing, modifying, or deleting customer data beyond what is necessary to demonstrate the vulnerability.
We commit to acknowledging your report within 48 hours, keeping you informed of our progress, and, where appropriate, publicly crediting your contribution.
Questions and Contact
For security-related questions, vulnerability reports, or to request our security documentation, please contact:
VoltLayer Security Team
Email: admin@voltlayer.ai
Privacy inquiries: admin@voltlayer.ai
General: admin@voltlayer.ai