Skip to content

Security

Security overview

Only controls that exist in the current build are listed. No certification or audit is claimed.

Posture

Voltacent is in private beta. This page states the security controls in place today — plainly, without certification language we have not earned.

No certifications claimed

We do not claim SOC 2, ISO 27001, or any third-party security audit. When we pursue them, it will be stated here.

Access requests

Requests are validated in the browser and again on the server against a strict schema with length limits before anything is stored. Automated submissions are blocked with a trap field, a minimum completion time, and per-connection rate limiting. Connections are identified by a one-way hash, never a raw IP address. The request table has row-level security with no public read or write policies — only server-side code can touch it.

Secrets handling

Privileged credentials live server-side and are never shipped to the browser.

Blast radius

This site holds no trading accounts, no client funds, and no order-routing credentials. No live market-data or execution system is connected to it. A compromise of the marketing site cannot reach trading infrastructure.

Not yet in place

Production monitoring, API-key authentication, and a published vulnerability-disclosure contact ship with the API launch. This page will be updated when they do.