Security and data
How Svolta handles data, access, logs, sub-processors, and the path to disclose a vulnerability.
Rules, access, and logs from day one.
Most AI incidents happen because the checks were added too late. We map source records, access rules, review points, and quality checks before build starts.
Security requirements vary with the workflow, systems, data, and deployment selected. Before implementation, the written scope identifies the relevant records, access roles, human review points, logs, provider dependencies, and responsibility boundaries. Controls described for one engagement do not automatically apply to another.
Managed infrastructure providers may publish their own certifications and attestations. Those documents describe provider controls. They do not certify Svolta. Ask security@svoltagroup.com for the evidence and engagement boundary relevant to your review.
Where customer data lives and for how long.
The deployment pattern decides where data sits. The retention policy decides how long it stays. Both are written into the engagement, not assumed.
Written deployment boundary
The Order or data processing agreement identifies the systems, data categories, deployment location, providers, access model, and isolation required for the engagement. A managed Svolta deployment, a client-owned cloud deployment, and an integration into an existing system have different boundaries. We do not present one pattern as universal.
Retention
Retention periods are set in writing for the data categories the workflow creates or processes. They depend on the client’s records obligations, incident-review needs, and provider capabilities. No general website retention period overrides an engagement’s Order or DPA.
Deletion and verification
Exit, handover, access revocation, export, and deletion obligations are those written in the engagement scope. Provider deletion capabilities and legally required retention can affect the process. We document the applicable procedure before promising a deletion method or attestation.
Providers that may be used.
This is a potential-provider inventory, not a statement that every provider processes every client's data. The Order or DPA records the providers used for an engagement.
- Managed edge runtime hostingPotential hosting provider for Svolta-built systems and provider for the public site. Applicable controls and provider evidence are reviewed per engagement.
- Managed Postgres databasePotential database provider for Svolta-built systems. Region, encryption, access, and provider evidence are confirmed in the engagement review.
- AnthropicPotential model provider where named in an engagement. Retention and training settings are verified for the selected account and recorded in scope.
- OpenAIPotential model provider where named in an engagement. Retention and training settings are verified for the selected account and recorded in scope.
- Microsoft AzurePotential cloud or model provider where an engagement is expressly scoped to Azure.
- Amazon Web ServicesPotential cloud, storage, or model provider where an engagement is expressly scoped to AWS.
- CloudflareEdge networking for the public site and a potential engagement provider where expressly scoped.
- GitHubPotential source-control provider where named in the engagement's delivery and access plan.
- LinearPotential engagement project-management provider. Permitted data and access are defined for the engagement.
Found something? Tell us.
Send enough detail for us to reproduce and assess the issue. Do not access data that is not yours or disrupt a production service.
Email security@svoltagroup.com with a description of the issue, the affected URL or system, and safe reproduction steps. Do not access other people’s data, degrade service, or use social engineering. We will assess the report and communicate through the contact details you provide. We do not publish a universal acknowledgement or remediation SLA on this page.
Start the security review.
Ask for the controls, provider documents, and engagement-specific data boundary relevant to your proposed workflow.
Email security@svoltagroup.com