Compliance · Mission 24/7
A consistent compliance posture, per framework.
Volgarde structures its compliance posture around four frameworks: SOC 2, ISO 27001, GDPR, and FAA/EASA alignment. For each, the current status and concrete commitments — encryption, audit logs, RBAC, EU hosting.
SOC 2
Security, confidentiality, availability, processing integrity and privacy — all five Trust Services Criteria covered, Type II targeted.
Current status· In progress · roadmap target
- At-rest and in-transit encryption across the full telemetry and radar data plane — five Trust Services Criteria covered.
- Signed audit log for every prediction and every agent action, exportable — auditor-ready.
- RBAC access policy via better-auth applied to the mission console and to exports — least privilege per role.
- SOC 2 scope: telemetry ingestion, radar table, MRO work-order storage.
- Annual Type II audit by a third-party firm (to initiate — Year 1 target).
- 24-hour incident policy documented and kept up to date — contracted client escalation.
ISO 27001
Documented ISMS — risk analysis and treatment, Annex A controls mapped, Statement of Applicability kept up to date.
Current status· In progress · roadmap target
- Documented ISMS — risk analysis, treatment, annual review; Annex A controls mapped.
- EU hosting (EU-West) by default, on-prem outposts available for strong-sovereignty fleets.
- At-rest and in-transit encryption — keys managed via HSM-capable KMS.
- ISMS scope extended to hosting sub-processors AWS / Azure / GCP, SoA kept up to date.
- Continuity plan and quarterly restore tests (to initiate).
- Annual management review and documented treatment of deviations.
GDPR
Volgarde acts as controller for site data and processor for fleet telemetry — DPA signed before any fleet processing.
Current status· In progress · operational baseline + DSR tooling
- Record of processing activities kept up to date — purposes limited to predictive maintenance; DPA signed before any fleet processing.
- DSR (access, rectification, erasure) tooling via /contact within 30 days.
- EU hosting by default; transfer outside the EU only under Standard Contractual Clauses — international transfers logged in the register.
- DPIA kept up to date, validated before any new telemetry or radar ingestion.
- Notification within 72 hours to the DPO / supervisory authority in case of incident.
- Documented retention policy — no retention beyond the stated purpose; archival schedule signed by the DPO.
FAA / EASA
Continuous alignment for predictive maintenance and observability — Part 5 SMS, Part-CAMO, ED-153, Continued Airworthiness accepted.
Current status· In progress · active on the pilots in flight
- End-to-end audit trail on every alert and every agent decision — defensible in front of PMI.
- Read-only MRO reporting, signed work-order export to Maximo / SAP PM / AVIATAR.
- Permanent traceability — not a one-off audit, continuous FAA / EASA alignment.
- Part 5 SMS / Part-CAMO tooling, ED-153 supported on Q1-Q2 pilot cohorts — Continued Airworthiness acceptance signed up-front.
- End-to-end FAA / EASA traceability available for client quality auditors.
- BYOK available for defence fleets — NIST 800-171 aligned.
Volgarde engagements
Four engagements, across all frameworks.
A consistent technical posture regardless of the framework: encryption, audit, RBAC, hosting.
- 01At-rest and in-transit encryption applied to the full data plane — telemetry, MRO, work-orders, radar.
- 02Signed audit logs for every agent prediction — exportable, defensible in front of a quality auditor.
- 03RBAC driven by better-auth — operator, mechanic, auditor, leadership roles — each with the right level of roll-up.
- 04EU hosting by default, on-prem outposts available for fleets that need strong sovereignty.
A security questionnaire to fill in?
Send it via the contact form — a Volgarde mission architect responds within 24 business hours with a calibrated quote and the associated security documentation.
(the form pre-fills the security-questionnaire intent)
Reply within 24 business hours