See it on your setup
Security

What is true today, said plainly.

This page claims only what is in place. What is still being built is not described here; it is answered on the call, against what is true on the day.

Certification.

Votis Technologies Ltd is Cyber Essentials certified. The certificate is on the public register.

ISO 27001 is in progress. We will say so here when it is certified, and not before.

The Cyber Essentials certificate

Your customers’ data.

What your customer tells the agent is used to configure their system. We do not repurpose it, and what the model provider behind the agent may do with it is a contract question rather than a code one, so it is on the list below rather than answered here.

Each customer’s data sits in its own database with its own credentials, so there is no other customer’s row in it to reach. We hold tests that prove a tenant cannot read across that line, and we run them against the database.

A document your customer sends is stored deliberately, with a record of what became of it: it was applied, it added nothing, or it could not be read. A file never just disappears.

Who can get in.

Your team signs in with multi-factor authentication, and you can require it for everybody in your organisation.

There are two portals, and they are never the same thing. Your team’s is where specifications are set out, agents are managed and configurations are signed off. Your customer’s is the configuration portal they get one link to, and it stays shut until you deliberately open it.

Nothing leaves unsigned.

Nothing goes near a target system until a person signs it off. The agent proposes and a person confirms; a decision the agent wrote is shown as proposed until someone says yes.

What the customer ruled out is recorded as ruled out, with the reason they gave, and that record is in front of you when you sign off.

What we answer on the call.

Where your data is hosted and in which region, who our sub-processors are and what the contract with them says about the data we send, whether your own identity provider can be used to sign in, how long we retain what, how we would tell you about an incident, what penetration testing has found, and what availability we commit to. We answer these against what is in place on the day you ask, rather than from a page that could go out of date.

Security questions and vulnerability reports go to security@votis.io.

security@votis.io

Ask us the rest.

A 20-minute call. Bring your security questionnaire and we will answer it line by line, with what is true on the day.

See it on your setup