Compliance · Mission 24/7

A consistent compliance posture, per framework.

Volgarde structures its compliance posture around four frameworks: SOC 2, ISO 27001, GDPR, and FAA/EASA alignment. For each, the current status and concrete commitments — encryption, audit logs, RBAC, EU hosting.

SOC 2

Security, confidentiality, availability, processing integrity and privacy — all five Trust Services Criteria covered, Type II targeted.

Current status· In progress · roadmap target

  • At-rest and in-transit encryption across the full telemetry and radar data plane — five Trust Services Criteria covered.
  • Signed audit log for every prediction and every agent action, exportable — auditor-ready.
  • RBAC access policy via better-auth applied to the mission console and to exports — least privilege per role.
  • SOC 2 scope: telemetry ingestion, radar table, MRO work-order storage.
  • Annual Type II audit by a third-party firm (to initiate — Year 1 target).
  • 24-hour incident policy documented and kept up to date — contracted client escalation.

ISO 27001

Documented ISMS — risk analysis and treatment, Annex A controls mapped, Statement of Applicability kept up to date.

Current status· In progress · roadmap target

  • Documented ISMS — risk analysis, treatment, annual review; Annex A controls mapped.
  • EU hosting (EU-West) by default, on-prem outposts available for strong-sovereignty fleets.
  • At-rest and in-transit encryption — keys managed via HSM-capable KMS.
  • ISMS scope extended to hosting sub-processors AWS / Azure / GCP, SoA kept up to date.
  • Continuity plan and quarterly restore tests (to initiate).
  • Annual management review and documented treatment of deviations.

GDPR

Volgarde acts as controller for site data and processor for fleet telemetry — DPA signed before any fleet processing.

Current status· In progress · operational baseline + DSR tooling

  • Record of processing activities kept up to date — purposes limited to predictive maintenance; DPA signed before any fleet processing.
  • DSR (access, rectification, erasure) tooling via /contact within 30 days.
  • EU hosting by default; transfer outside the EU only under Standard Contractual Clauses — international transfers logged in the register.
  • DPIA kept up to date, validated before any new telemetry or radar ingestion.
  • Notification within 72 hours to the DPO / supervisory authority in case of incident.
  • Documented retention policy — no retention beyond the stated purpose; archival schedule signed by the DPO.

FAA / EASA

Continuous alignment for predictive maintenance and observability — Part 5 SMS, Part-CAMO, ED-153, Continued Airworthiness accepted.

Current status· In progress · active on the pilots in flight

  • End-to-end audit trail on every alert and every agent decision — defensible in front of PMI.
  • Read-only MRO reporting, signed work-order export to Maximo / SAP PM / AVIATAR.
  • Permanent traceability — not a one-off audit, continuous FAA / EASA alignment.
  • Part 5 SMS / Part-CAMO tooling, ED-153 supported on Q1-Q2 pilot cohorts — Continued Airworthiness acceptance signed up-front.
  • End-to-end FAA / EASA traceability available for client quality auditors.
  • BYOK available for defence fleets — NIST 800-171 aligned.

Volgarde engagements

Four engagements, across all frameworks.

A consistent technical posture regardless of the framework: encryption, audit, RBAC, hosting.

  • 01At-rest and in-transit encryption applied to the full data plane — telemetry, MRO, work-orders, radar.
  • 02Signed audit logs for every agent prediction — exportable, defensible in front of a quality auditor.
  • 03RBAC driven by better-auth — operator, mechanic, auditor, leadership roles — each with the right level of roll-up.
  • 04EU hosting by default, on-prem outposts available for fleets that need strong sovereignty.
Security · Client questionnaire

A security questionnaire to fill in?

Send it via the contact form — a Volgarde mission architect responds within 24 business hours with a calibrated quote and the associated security documentation.

(the form pre-fills the security-questionnaire intent)

Submit a security questionnaire →

Reply within 24 business hours