"Compliance" means different things depending on your industry and who's asking: a client's security questionnaire, an internal audit, a regulator, or a cyber-insurance renewal. Vouchio doesn't publish a list of third-party certifications on this site; instead, here's what's actually available and how it typically maps to common requirements, so you can check it against whatever you're being asked to meet.

Retention Lock: meeting "must retain and can't be altered" requirements

Many compliance frameworks require that certain records, financial documents, contracts, communications, be kept for a fixed period and be provably unaltered during that window. Retention Lock, available on Archive Storage, uses a write-once-read-many model: once a retention period is set on a record, it can't be shortened, modified, or deleted by anyone, including a compromised admin account or Vouchio itself, until the period expires.

Set the retention period to match your actual requirement Retention rules vary widely by document type and jurisdiction. Confirm the specific period your requirement calls for with whoever owns compliance at your business before setting the lock; Vouchio enforces whatever period you set, it doesn't advise on what that period should be.

Access logs: meeting "who touched this and when" requirements

Compliance-ready access logs record account-level access activity, useful for audits that ask who accessed or modified specific records and when. This is separate from Retention Lock: logging tells you what happened, Retention Lock prevents certain things from happening at all.

Data residency and international transfers

If your requirement specifies where data must physically reside, ask about this directly in your questionnaire before signing up. Vouchio's infrastructure is organized by region, and Recovery Ready includes offsite replication for disaster recovery purposes; the details of which regions apply to your account are confirmed during onboarding, not published generically here since they depend on your plan and location.

Encryption

Data is encrypted at rest and in transit on every plan tier, not as an add-on reserved for higher-priced plans. This satisfies the encryption baseline in most frameworks, though some specific requirements ask about particular algorithms or key-management arrangements; ask us directly if your requirement is that specific.

What to do if you need a specific certification confirmed

If a client, auditor, or regulator has asked you to confirm a specific certification or standard, don't assume based on this page. Note the exact requirement in your questionnaire, or email security@vouchio.net directly, and a specialist will tell you plainly whether it's currently supported, rather than leaving it ambiguous.

Requirement typeRelevant Vouchio feature
Records can't be altered or deleted for N yearsRetention Lock (Archive Storage)
Must show who accessed data and whenCompliance-ready access logs
Data must be encrypted at rest and in transitStandard on every plan tier
Data must reside in a specific regionConfirmed per account during onboarding
Specific certification (e.g. named to you by an auditor)Ask directly, don't assume

For more on the security practices behind all of this, see the Security Manifesto.

Have a specific compliance requirement?

Tell us exactly what's being asked of you in the questionnaire and we'll give you a straight answer.

Get your quote