Know where your data lives, who can act and what changed.

Volts separates customer access, limits sensitive actions through roles and approvals, and records supported platform events—so IT, operators and auditors can examine the controls before deployment.

Six answers your security team should not have to guess.

Each answer below is kept in step with your customer agreement, the privacy notice and how the product actually behaves.

Where is customer data hosted?

Where your data is hosted, who processes it and which subprocessors are involved is set out in the Security Brief, named and dated.

Hosting location Subprocessors Data residency

Who can see each organisation and site?

Access is assigned by role and by site, so a user sees only the portfolios and buildings they have been given.

Organisation isolation Role-based access Site scope

What can automation act on?

Sensitive actions run through the approval rules you configure, and execution can be stopped from the platform.

Human approval Safety rules Emergency stop

Which events are recorded?

Volts records the actions taken in the platform - who did what, when, and what changed. The exact event coverage and retention are listed in the Security Brief.

Event coverage Retention Export

How is data protected and recovered?

Encryption, backup and restore practice is documented and dated in the Security Brief rather than summarised here.

Encryption Backups Restore testing

What can tenants see?

A tenant user sees the consumption, charges and documents for their own unit, and nothing outside it.

Tenant scope Reading evidence Portfolio separation

Personal data collected on this website is governed by the Privacy Policy. Data processed for customers inside the platform is governed by the customer agreement and, where applicable, the Data Processing Agreement.

Read the Privacy Policy

FAQ

Eight security questions answered for due diligence.

Where is our data stored and processed?

The hosting provider, the region and the current subprocessor list are named in the Security Brief. Request it and we will send the current version.

Who inside our organisation can see what?

Administrators assign roles, and scope them to the organisation, portfolio or individual site. The permission matrix and default role settings are available in the Security Brief.

What do tenants get to see?

A tenant sees their own unit and the common information you choose to share. Confirm the final permissions during commissioning before inviting any tenant user.

Can we require multi-factor authentication?

Authentication options, including MFA and SSO, are listed in the Security Brief.

Can Volts control building equipment without approval?

Execution depends on the permissions and workflow agreed for each point. You decide which actions need human approval and which, if any, may run autonomously.

Which actions appear in the audit log?

The event coverage, retention period and export route are listed in the Security Brief.

What happens during an incident or outage?

Incident response, notification windows and restoration targets are set out in the Security Brief and in your contract.

Can we export or delete our data at contract end?

Your readings are your data and can be exported. Contract-end retention and deletion are governed by the DPA.

Put the controls in front of IT before the pilot starts.

Request the current security brief, subprocessor list and DPA, then bring your access, hosting and audit requirements into the first-site scope - not after commissioning.