"Compliance" means different things depending on your industry and who's asking: a client's security questionnaire, an internal audit, a regulator, or a cyber-insurance renewal. Vouchio doesn't publish a list of third-party certifications on this site; instead, here's what's actually available and how it typically maps to common requirements, so you can check it against whatever you're being asked to meet.
Retention Lock: meeting "must retain and can't be altered" requirements
Many compliance frameworks require that certain records, financial documents, contracts, communications, be kept for a fixed period and be provably unaltered during that window. Retention Lock, available on Archive Storage, uses a write-once-read-many model: once a retention period is set on a record, it can't be shortened, modified, or deleted by anyone, including a compromised admin account or Vouchio itself, until the period expires.
Access logs: meeting "who touched this and when" requirements
Compliance-ready access logs record account-level access activity, useful for audits that ask who accessed or modified specific records and when. This is separate from Retention Lock: logging tells you what happened, Retention Lock prevents certain things from happening at all.
Data residency and international transfers
If your requirement specifies where data must physically reside, ask about this directly in your questionnaire before signing up. Vouchio's infrastructure is organized by region, and Recovery Ready includes offsite replication for disaster recovery purposes; the details of which regions apply to your account are confirmed during onboarding, not published generically here since they depend on your plan and location.
Encryption
Data is encrypted at rest and in transit on every plan tier, not as an add-on reserved for higher-priced plans. This satisfies the encryption baseline in most frameworks, though some specific requirements ask about particular algorithms or key-management arrangements; ask us directly if your requirement is that specific.
What to do if you need a specific certification confirmed
If a client, auditor, or regulator has asked you to confirm a specific certification or standard, don't assume based on this page. Note the exact requirement in your questionnaire, or email security@vouchio.net directly, and a specialist will tell you plainly whether it's currently supported, rather than leaving it ambiguous.
| Requirement type | Relevant Vouchio feature |
|---|---|
| Records can't be altered or deleted for N years | Retention Lock (Archive Storage) |
| Must show who accessed data and when | Compliance-ready access logs |
| Data must be encrypted at rest and in transit | Standard on every plan tier |
| Data must reside in a specific region | Confirmed per account during onboarding |
| Specific certification (e.g. named to you by an auditor) | Ask directly, don't assume |
For more on the security practices behind all of this, see the Security Manifesto.
Have a specific compliance requirement?
Tell us exactly what's being asked of you in the questionnaire and we'll give you a straight answer.
Get your quote