Security

Security is part of the intelligence

Effective · July 16, 2026

Security requirements differ across model providers, private knowledge systems, agent tools, multimodal data, and deployment environments. We define controls according to project risk, data sensitivity, model architecture, autonomy, and the client’s operating environment.

Our baseline

  • Encrypted transport for supported production systems.
  • Managed secrets and environment separation; credentials are not committed to source code.
  • Least-privilege access, authenticated repositories, and removal of access after engagement.
  • Peer review, dependency and model-supply-chain review, input and output validation, and secure defaults appropriate to the architecture.
  • Logging, monitoring, backup, recovery, and model evaluation requirements defined for production scope.

Client environments

Clients control their accounts, users, production infrastructure, data classification, model-provider agreements, and business continuity unless a statement of work explicitly assigns those responsibilities to us. We document handover items and recommend controls relevant to the system delivered.

Models, retrieval, and agents

AI systems may require scoped model and tool access; isolation between retrieval sources and users; prompt-injection and data-exfiltration defenses; constrained outputs; least-privilege agent permissions; approval gates; sensitive-data filtering; and limits on retention, spend, and actions. Controls are selected from the project threat model rather than assumed to be universal.

Evaluation and human review

We may use adversarial evaluations, red-team scenarios, output validation, source verification, and regression suites to expose identified model risks. Consequential outputs or actions may require human review and recoverable workflows. These measures reduce risk but cannot eliminate every unpredictable model behaviour.

Third parties

Cloud platforms, model and inference providers, open-source models, datasets, packages, APIs, and other vendors have independent security responsibilities. We select and configure them with reasonable care and review relevant terms where in scope, but no system, model, or provider can guarantee absolute security.

Responsible disclosure

If you believe you found a vulnerability in this website or a system we operate, email support@volumelabs.live. Include the affected location, impact, and reproduction steps. Do not access third-party data, disrupt service, or publicly disclose the issue before we can investigate.

Project security enquiries

Threat modelling, security questionnaires, model and data-flow reviews, provider assessments, red-team evaluation, and data-processing requirements can be discussed before an engagement and included in project scope.