Security

Enterprise-Grade Security

Security is foundational to Volari, not an afterthought. Your calendar, goals, and execution data are protected with the same standards trusted by Fortune 500 companies.

HIPAA ReadyBAA Included
GDPR Compliant
AES-256 Encryption

Your Data, Fully Protected

End-to-End Encryption

AES-256 encryption at rest. TLS 1.2+ for all data in transit. Sensitive credentials encrypted with unique IVs and GCM authentication tags.

Granular Data Control

You choose which calendars, integrations, and data sources Volari can access. Revoke any connection at any time from Settings.

Data Retention & Deletion

Request full account deletion at any time. Data purged within 30 days. Inactive accounts anonymized after 90 days. Payment records retained 7 years per tax law.

AI You Can Trust

No Model Training on Your Data

Your calendar events, goals, and conversations are never used to train AI models. We use Anthropic Claude with zero-retention data processing agreements.

Zero Data Retention by Providers

Our AI providers (Anthropic, OpenAI Whisper) do not store your data after processing. Prompts and responses are ephemeral.

Prompt Injection Protection

All user inputs are sanitized before reaching AI models. Structured tool execution prevents unauthorized actions. Calendar writes are rate-limited and audited.

Rigorous Access Control

Role-Based Permissions

Five-tier RBAC (Owner, Admin, Manager, Member, Viewer) with row-level security. Team members only see what they need to see.

OAuth-Based Authentication

Sign in with Google or Microsoft. JWT-validated sessions with automatic token refresh. No passwords stored by Volari.

Audit Logging

Sensitive operations (account changes, OAuth revocations, subscription modifications) are logged with IP address, timestamp, and context.

Infrastructure & Operations

Cloud Hosting

Hosted on Vercel (AWS-backed) with automatic failover, edge caching, and DDoS protection. Database on Supabase (AWS) with point-in-time recovery.

Rate Limiting

Tiered rate limiting across all endpoints. Calendar write operations capped at 20/hour per user. Webhook signatures verified with HMAC-SHA256.

Stripe Payment Security

All payment processing handled by Stripe (PCI DSS Level 1). Volari never sees or stores card numbers. Webhook payloads cryptographically verified.

Compliance

GDPRCompliant

Full compliance with EU General Data Protection Regulation. Data processing agreements available.

CCPA / CPRACompliant

California Consumer Privacy Act compliance. Opt-out and deletion rights fully supported.

SOC 2 Type IIIn Progress

Audit underway. Automated evidence collection via compliance platform. Target completion Q3 2026.

HIPAAReady

HIPAA-ready with signed BAAs for all healthcare customers. Documented breach response plan, data retention policy, and technical safeguards.

HIPAA Compliance for Healthcare

Volari is built to serve healthcare practices. We sign Business Associate Agreements with every healthcare customer and maintain the technical, administrative, and physical safeguards required by HIPAA.

Business Associate Agreement

BAA included with every healthcare contract. Covers permitted uses, prohibited disclosures, breach notification commitments, and data return obligations.

Technical Safeguards

AES-256 encryption at rest. TLS 1.2+ in transit. Role-based access control with 124+ row-level security policies. MFA available. Automatic session termination.

Breach Response

Documented incident response plan with 30-day notification commitment. Detection, containment, notification, and remediation procedures defined and tested.

Audit Logging

All data access logged with agent, action, target, and timestamp. Audit logs retained for 6 years per HIPAA requirement (45 CFR § 164.530(j)).

Data Retention Policy

Documented retention schedule for all data types. PHI returned or destroyed within 30 days of service termination, with written certification.

Infrastructure

Supabase (SOC 2 Type II) and Vercel (SOC 2 Type II) infrastructure. US-based data residency (AWS us-east-1). Daily automated backups with point-in-time recovery.

Request a BAA: Contact us at security@volari.ai to request a Business Associate Agreement for your practice. BAAs are included at no additional cost.

Subprocessors

We maintain a transparent list of all third-party services that process your data. We provide 30 days advance notice before adding new subprocessors.

View full subprocessor list →

Questions about security?

We're happy to walk through our security posture, complete vendor questionnaires, or set up a call with our team.

Contact security teamRead privacy policy