Your strategy is your most sensitive asset
Vouli IQ holds the AI strategy of CXOs, GCC heads, and boards. It is engineered for strict per-organisation isolation, data-residency choice, and full auditability — with responsible-AI practices built into how it reasons.
Architectural controls
Security by architecture, not afterthought
Per-organisation isolation
Every record is scoped to your organisation and enforced at the database layer through row-level security — not just in application code. Your data never bleeds across tenants.
Encryption in transit & at rest
All traffic is encrypted over TLS, and data is encrypted at rest by the managed database platform.
Scoped API access
Programmatic access uses scoped API keys with per-key rate limits, so integrations get exactly the access they need — and no more.
Immutable audit trail
Sensitive actions are recorded to an append-only audit log, providing the evidence trail expected for SOC 2-grade governance.
Role-based access control
Admin, contributor, and viewer roles per organisation ensure people see and change only what their role permits.
Managed, hardened infrastructure
Built on managed cloud infrastructure with platform-level patching, backups, and monitoring.
Data residency
Where your data lives
Every organisation is provisioned to a residency region. Today all customer data is stored in our Tokyo (AWS ap-northeast-1) cell; dedicated EU and India cells are on our roadmap and provisioned for Enterprise customers on request.
Asia-Pacific (Tokyo)
ap-northeast-1
Platform default — all customer data is stored in AWS Tokyo today.
European Union
eu-central-1
For GDPR data-residency requirements — on our roadmap; provisioned for Enterprise customers on request.
India
ap-south-1
For GCCs and India-domiciled enterprises with DPDP considerations — on our roadmap; provisioned for Enterprise customers on request.
Compliance alignment
Built to help you meet the standards that matter
Vouli IQ is designed to help your organisation align to the frameworks below and produce board-ready evidence. Framework alignment supports your own compliance programme; it is not a substitute for independent certification.
NIST AI RMF
Risk modelling and the Compliance Engine map to the NIST AI Risk Management Framework.
ISO 42001
AI management-system practices aligned to the ISO/IEC 42001 standard.
SOC 2 principles
Audit logging and access controls designed around SOC 2 trust-service criteria.
GDPR
Privacy controls and scheduled-erasure execution to support GDPR obligations; a dedicated EU residency cell is on the roadmap.
India DPDP
Practices aligned to the India DPDP Act; a dedicated India residency cell is on the roadmap.
OWASP LLM Top 10
Responsible-AI guidance informed by the OWASP Top 10 for LLM applications.
Responsible AI
Intelligence you can defend
Transparency
AI outputs cite the frameworks and reasoning behind them, so recommendations are explainable at the board table.
Human in the loop
Vouli IQ informs decisions; it does not make them autonomously. Leaders remain accountable for every strategic call.
Provenance & versioning
Every AI output is versioned with its model, prompt context, and timestamp — a full provenance record over time.
Vulnerability disclosure
Found a security issue? Tell us — safely.
- Report privately to care@vouliiq.com (also published machine-readably at /.well-known/security.txt). Include steps to reproduce; please do not access data that is not yours.
- We acknowledge within 3 business days, keep you informed while we investigate, and credit reporters who wish to be named once a fix ships.
- Good-faith research is welcome. We will not pursue action against researchers who follow this policy, avoid privacy violations and service disruption, and give us reasonable time to remediate before public disclosure.
Have a security review? We'll meet it.
We're happy to walk your security and compliance teams through our architecture and controls.
Request a demoOr email care@vouliiq.com