Security and governance

Our engineers, with your badge.

We take on execution within your processes. Your team controls access, changes and architecture.

Our work follows your governance.

From first access to delivery, we follow the workflows agreed with your team.

01

Scoped access.

We define identities, permissions and owners before connecting systems.

02

Approved changes.

Our engineers follow your change review and authorization process.

03

Recorded delivery.

We document decisions and gather the evidence agreed for your operation.

Deployment follows your architecture.

Self-hosted and BYOC define where to run. BYOK adds customer-managed keys. Compatibility is assessed for each scope.

Self-hosted

Software in your environment.

Voidr components within the perimeter agreed with Architecture and Security.

Technical details
Environment
Cloud or on-premises, depending on component compatibility.
Connectivity
Services, integrations and model endpoints are declared before deployment.
Operations
Access, retention, backup, updates and responsibilities are defined in the deployment plan.
Acceptance
The client reviews evidence and applicable controls before operation.
Bring Your Own Cloud

Resources in your account.

Eligible services in your cloud account, under your network and region policies.

Technical details
Providers
AWS, Azure and Google Cloud, subject to architecture assessment.
Perimeter
Components, processing and data flows are defined in the technical design.
Management
Region, network, costs and operational responsibilities are agreed with your Cloud team.
External connections
Required model endpoints, integrations and telemetry are declared for approval.
Bring Your Own Key

Keys under your control.

Integration with a compatible KMS or HSM, with documented permissions and scope.

Technical details
Master key
Managed by the client; integration depends on the contracted components.
Encryption
Covered data, provider, algorithms and availability are defined during assessment.
Lifecycle
Rotation, revocation and recovery are validated in the deployment environment.
Audit
Logs and evidence depend on approved components and controls.
Technical reference

Answers for technical assessment.

Review what we define with Security and Architecture before deployment.

Identity and access

Permissions, integrations and engineer access lifecycle.

How do engineers access the environment?
Access follows client processes. Identities, permissions and authorization owners are documented for the scope.
How are access changes handled?
The assessment defines provisioning, review and revocation. Authentication, API scopes and least privilege are assessed per integration.

Changes and software security

Review, authorization and vulnerability handling.

Who authorizes changes?
The client defines approval workflows. Voidr executes within them and records agreed decisions and evidence.
How are dependencies and vulnerabilities assessed?
Review follows the applicable development lifecycle. Vulnerability handling and available evidence are documented for the scope.

Data and privacy

Purpose, location, retention and deletion.

What data enters the solution?
The assessment defines required data, purposes and processing boundaries. Data, metadata and telemetry are described in the architecture.
Where is it stored and for how long?
Residency, retention and deletion are agreed per deployment. LGPD and GDPR requirements are assessed according to the processing and applicable terms.

Encryption and keys

KMS, HSM, rotation and revocation with BYOK.

Can we use our own keys?
BYOK depends on compatibility with the client KMS or HSM. The design defines covered data, permissions and responsibilities.
What happens when a key is revoked?
Revocation, rotation and recovery effects are validated in the deployment components before operation.

AI models and external connections

Endpoints, data transfers and usage terms.

Does self-hosting eliminate external connections?
Not necessarily. Models, integrations and telemetry may require external endpoints. These are declared and assessed before deployment.
What is sent to models?
The design defines required data and endpoints. Provider usage, retention and terms are assessed for the approved scope.

Logs and continuity

Evidence, backup, recovery and escalation.

What records are available?
Logs, audit trails and monitoring depend on contracted components. We define what to record, how to access it and how long to retain it.
Who owns continuity?
Backup, recovery, operational responsibilities and escalation channels are agreed during technical assessment.

Subprocessors and responsibilities

Third parties and deployment boundaries.

Which third parties process data?
The effective list depends on deployment. Providers, purposes and locations are formalized in the scope and applicable terms.
How does this work with BYOC?
Compatible services run in the client account. External flows and third parties are still assessed and documented.

Bring your Security team into the conversation.

Together, we define the perimeter, responsibilities and evidence needed to approve deployment.