VOLUME
Trust center

Your data. Your rules.

We built VOLUME to earn back the trust that Big Real Estate software has burned. That means fewer cookies, clearer data handling, plain-language legal, and the ability to walk away with everything you paid us to make — anytime.

01 · Practices

How we handle the stuff you send us.

01

Encryption at rest + in transit

Every byte you send us is TLS 1.3 in transit. Postgres, storage, and backups are encrypted at rest via industry-standard AES-256. Secrets live in Vercel's environment vault — never in the repo.

02

Least-privileged access

Row-level security policies are the primary access control. Even a stolen anon key can't read another workspace's tours. Service-role access is limited to a small set of vetted server-side routes.

03

Password hygiene

We enforce a 10+ character minimum with mixed case, digits, and symbols. Every password is checked against the haveibeenpwned breach corpus at sign-up — via k-anonymity, so your password never leaves your browser.

04

Audit trail

Every workspace-level action (invite, role change, tour publish, tour delete) is logged. Owners can request a full export for the last 12 months of activity.

05

Right to portability

You can download every tour as a .ply file at any time — no export button hidden behind a Pro plan, no proprietary format lock-in. If you leave, you leave with your data.

06

Right to be forgotten

Delete your account and every associated tour, lead, and analytics event is permanently removed within 30 days. We keep audit logs for 12 months for security review, then those are purged too.

02 · Sub-processors

Every third party that touches your data.

These are the vendors we've chosen to run VOLUME on. If we ever add or remove one, we'll update this list and notify subscribed customers 30 days in advance.

VendorRoleData locationPrivacy
VercelEdge network + serverless functionsUSA / globalPolicy →
SupabasePostgres, auth, storageUSA (AWS us-east-1)Policy →
CloudflareR2 object storage for splat filesGlobalPolicy →
MakeSplatGaussian-splat reconstructionUSAPolicy →
StripePayments + subscription billingUSA / IrelandPolicy →
SentryError + performance telemetryUSAPolicy →
ResendTransactional email deliveryUSA / EUPolicy →

If we don't need it, we don't collect it.

the rule we set on day one
03 · Compliance

Where we are, where we're going.

Live today

GDPR + CCPA aligned

Cookie consent center, right to portability, right to be forgotten, data-processing addendum available on request. We treat every user like a GDPR user by default — no matter their jurisdiction.

Live today

Cookie & tracker transparency

We use essential cookies for auth + Vercel Analytics for page-view stats + Sentry for errors. No ad-tech, no marketing pixels, no third-party trackers. You can toggle any category at any time.

In progress

SOC 2 Type II

Type I readiness audit scheduled Q1 2027. Full Type II observation window Q2–Q4 2027. If you need a signed security questionnaire before, we can walk through it call-first.

In progress

Data residency options

Currently US (Supabase us-east-1 + Cloudflare R2). EU-region availability targeted mid-2027 for customers who require it.

04 · Responsible disclosure

Find a bug? Tell us first.

Security researchers who report vulnerabilities in scope get credit on this page and a personal thank-you from the team. Send findings to security@volumevirtual.com — include a repro, expected vs actual, and (if relevant) a PoC. We reply within 3 business days.

Our security.txt has the machine-readable version.

Need a DPA or security questionnaire?

Real signature, real turnaround. If you're procuring VOLUME for a team of 10+, we'll get you what you need to close.