Security

Enterprise-Grade Security

Security is foundational to Volari, not an afterthought. Your calendar, goals, and execution data are protected with the same standards trusted by Fortune 500 companies.

GDPR Compliant
SOC 2 Type IIIn Progress
AES-256 Encryption

Your Data, Fully Protected

End-to-End Encryption

AES-256 encryption at rest. TLS 1.2+ for all data in transit. Sensitive credentials encrypted with unique IVs and GCM authentication tags.

Granular Data Control

You choose which calendars, integrations, and data sources Volari can access. Revoke any connection at any time from Settings.

Data Retention & Deletion

Request full account deletion at any time. Data purged within 30 days. Inactive accounts anonymized after 90 days. Payment records retained 7 years per tax law.

AI You Can Trust

No Model Training on Your Data

Your calendar events, goals, and conversations are never used to train AI models. We use Anthropic Claude with zero-retention data processing agreements.

Zero Data Retention by Providers

Our AI providers (Anthropic, OpenAI Whisper) do not store your data after processing. Prompts and responses are ephemeral.

Prompt Injection Protection

All user inputs are sanitized before reaching AI models. Structured tool execution prevents unauthorized actions. Calendar writes are rate-limited and audited.

Rigorous Access Control

Role-Based Permissions

Five-tier RBAC (Owner, Admin, Manager, Member, Viewer) with row-level security. Team members only see what they need to see.

OAuth-Based Authentication

Sign in with Google or Microsoft. JWT-validated sessions with automatic token refresh. No passwords stored by Volari.

Audit Logging

Sensitive operations (account changes, OAuth revocations, subscription modifications) are logged with IP address, timestamp, and context.

Infrastructure & Operations

Cloud Hosting

Hosted on Vercel (AWS-backed) with automatic failover, edge caching, and DDoS protection. Database on Supabase (AWS) with point-in-time recovery.

Rate Limiting

Tiered rate limiting across all endpoints. Calendar write operations capped at 20/hour per user. Webhook signatures verified with HMAC-SHA256.

Stripe Payment Security

All payment processing handled by Stripe (PCI DSS Level 1). Volari never sees or stores card numbers. Webhook payloads cryptographically verified.

Compliance

GDPRCompliant

Full compliance with EU General Data Protection Regulation. Data processing agreements available.

CCPA / CPRACompliant

California Consumer Privacy Act compliance. Opt-out and deletion rights fully supported.

SOC 2 Type IIIn Progress

Audit underway. Automated evidence collection via compliance platform. Target completion Q3 2026.

HIPAARoadmap

Business Associate Agreements available for healthcare organizations upon request.

Subprocessors

We maintain a transparent list of all third-party services that process your data. We provide 30 days advance notice before adding new subprocessors.

View full subprocessor list →

Questions about security?

We're happy to walk through our security posture, complete vendor questionnaires, or set up a call with our team.

Contact security teamRead privacy policy