Security

Security

Your trade compliance data is sensitive. This page describes current platform controls and protections provided by our infrastructure providers.

Platform controls

Encryption in Transit & at Rest

Our infrastructure providers (Supabase and Railway) provide encryption features for data in transit and at rest.

Security Controls

The platform uses access controls, logging, and infrastructure-provider encryption features.

API Key Authentication

Plaintext API keys are shown once, stored as hashes, and can be revoked or rotated from the dashboard; selected public endpoints do not require a token.

Multi-Tenant Isolation

Each customer's data is isolated via row-level security policies. Your compliance data is not shared with other customers.

Audit Logs

Audit trail of classification requests, screening results, and compliance decisions with SHA-256 hash chaining for integrity verification.

Data Retention & Deletion

Retention varies by workflow and service configuration. Contact support@voraprotocol.com with data-retention or deletion questions.

Supported Sanctions Lists

We screen against the supported sanctions and restricted-party lists shown below. Source availability and synchronization can vary.

Sanctions Lists & Update Frequency

ListDescriptionUpdate
OFAC SDN ListOffice of Foreign Assets Control Specially Designated NationalsAs designations occur (polled daily)
EU Consolidated ListEuropean Union sanctions and restricted parties (FSF)Approx. daily (RSS change feed)
UN Security CouncilUnited Nations sanctions listAs published by the UN
BIS Entity ListBureau of Industry and Security restricted entitiesAs published by BIS
UK Sanctions ListUK Sanctions List (published by FCDO/OFSI)As designations occur

Security Practices

Secure code reviews and static analysis
Automated dependency scanning
Least-privilege access controls
Documented backup and recovery procedures are being implemented.
Incident response procedures

Current Security Posture

Below are implemented technical controls. No third-party certification is claimed here.

SHA-256 Audit Trail

Implemented

Classification, screening, and compliance records can be included in a hash-chained audit trail.

Provider Encryption

Implemented

Our infrastructure providers support encryption for customer data in transit and at rest.

JWT Authentication

Implemented

Stateless signed session tokens with Supabase Auth; optional per-tenant API keys.

Responsible Disclosure

We welcome security researchers to report vulnerabilities. If you discover a security issue, please report it responsibly.

Reports should include: description of the vulnerability, steps to reproduce, and potential impact assessment.

Security Contact

For security inquiries, vulnerability reports, or to request our security questionnaire, email us at support@voraprotocol.com with "Security" in the subject line.

support@voraprotocol.com