Security
What happens to your matters here.
Six controls, each one a mechanism you can watch working, and a plain list of what we do not have yet. Nothing on this page is a badge we have not earned.
Request a demoHow your matters are handled
Each of these names the mechanism, not the intention. Every one is in the product today.
No training on your data
Every model call goes to Amazon Bedrock, which does not train on what is sent to it. There is no second AI vendor and no direct provider API anywhere in the product, so there is no side channel to qualify that with.
Handled in the EU
Your files, your database and the application itself run in AWS Frankfurt, eu-central-1. Nothing about the product is deployed outside that region.
Isolated by firm
Every query carries your firm’s identifier from the signed-in session, as a required argument rather than an optional filter. A document identifier on its own does not resolve: the record is fetched by document and firm together, or not at all.
Approval before anything leaves
Everything that leaves the firm queues for a human decision: client messages, calendar invitations, payment requests. It writes an approval card and waits. Read-only lookups, like the land registry or the case-law databases, run without a gate.
Every change visible
Drafting arrives as native Word tracked changes, each carrying a severity and a one-line reason, which you accept or reject. The previous version is kept, so nothing is overwritten.
Yours to take away
Download any document at any time and what you get is the .docx itself, under its own filename. Not an export format and not a re-render, but the same file Word opens.
Certifications: the plain answer
We hold no SOC 2 report, no ISO 27001 certificate, no CCPA attestation and no independent penetration test. You will not find a badge on this page, and you will not find a “coming soon” where one should be.
The reason is worth stating plainly, because it is a scheduling fact rather than an effort one. A SOC 2 Type II report describes controls operating over an observation window, and a window cannot be created retroactively. The expensive act is starting the clock, which means operating the controls and leaving the evidence. That is what the work above is for.
What you can see instead
The approval card
Every queued action becomes a card in the thread, naming who approved it and when. The approval is the audit record, not a log written beside one.
The tool trail
Every step the worker took is written into the conversation as it happens, in order, with its result. Nothing runs where you cannot see it.
The source of every fact
A fact drawn from your files carries a chip back to the span it came from, so a claim in a draft can be traced to the page it was read on.
None of these is a certificate. All of them are things you can ask us to show you in a demo, which is a different kind of evidence and, for this question, a better one.
The questions your IT team will ask
These are the questions that arrive in round two, once this page has been forwarded to somebody whose job is to find the problem with it. Answered here the way we would answer them on a call, including the places where the answer is no.
Request a demoWhat counts as our data?
Everything you upload and everything the product derives from it: the documents, the facts extracted from them, the drafts, and the threads where the work happened. The derived material is yours on the same terms as the files, because it carries the same content.
Do you train on it?
No. Model calls go to Amazon Bedrock, which does not train on the inputs it is sent, and there is no other model provider in the product. We have no training pipeline of our own, and your work is not used to improve anything anyone else sees.
Where is it stored, and where is it processed?
Stored in AWS Frankfurt, eu-central-1, together with the database and the application itself. Model inference runs on European inference profiles in the same region.
Who at Volares can see our matters?
Today the honest answer is that operational access is not separated from support access, and there is no access log you can query for yourself. Role separation and an exportable access audit are designed and not built. We would rather you learn that here than find it in a questionnaire.
How is one firm’s work kept from another’s?
Every read carries your firm’s identifier from the signed-in session, as a required argument on the query rather than a filter that can be left off. A document identifier on its own does not resolve. This is enforced in the application rather than by the database, which is a real distinction and one we will put to your IT team in those words.
What stops the product sending something to a client by mistake?
Classification. Every capability a worker can call is marked internal or queued, and everything that leaves the firm is queued: it writes an approval card and stops there. There is no configuration in which an outbound message sends itself, and the card is the record that it was authorised.
Do you hold SOC 2 or ISO 27001?
No, and no other certification or attestation either. The section above says why the answer is a matter of elapsed time rather than intent, and what we can show you in their place.
What happens to our files if we leave?
Every document downloads as its own .docx, at any time, without asking us. What we do not have yet is a written retention and deletion schedule. It is one of the documents we owe and are drafting, and until it exists you should treat deletion as a request you make to us rather than a control you hold.