Legal
Security overview
The evidence boundary for Votegrain security and operational commitments.
- Audience
- Customers, security reviewers and authorised users
- Version
- SECURITY-2026-08-29-V1
- Effective date
- 2026-08-29
Security approach
Votegrain applies layered product, database, provider and operational controls proportionate to a controlled organisational pilot. This overview distinguishes current controls from service levels that are not sold. A source-code path or environment variable alone is not treated as operational evidence.
Product and data safeguards
- Database-backed tenant, organisation and role boundaries, including row-level security and permission tests for protected data paths.
- Individual authentication sessions, controlled administrator roles and account-access removal through the supported operational path.
- Governed write-once ballot submission, eligibility and duplicate-vote controls, aggregate result surfaces and small-cell suppression for anonymous reporting.
- Provider-managed encryption in transit and at rest, protected production secrets, dependency and patch review, redacted diagnostic monitoring and daily database backups.
- Confidentiality duties and least-privilege, purpose-limited support access using individual authentication.
Current product boundaries
The service uses database-backed tenant and organisation permissions, governed write-once ballot paths, aggregate reporting and small-cell suppression controls. Those controls reduce risk but do not make a vote cryptographically anonymous, certify a customer's governance process or prevent every inference from information exported by a customer.
Accepted ballots and bounded audit references may remain after an account record changes or is deleted so the service can preserve decision integrity and evidence. The DPA limits that exception, its retention and access.
Service and support boundary
- Support is staffed 09:00–17:00 UK time, Monday to Friday excluding public holidays in England. Initial-response targets are four staffed hours for Priority 1 and two business days for other requests.
- Votegrain gives reasonable notice of planned maintenance where practicable and may perform urgent maintenance without advance notice where delay would increase security or service risk.
- The first pilot has no uptime SLA, service credits, recovery-point objective, recovery-time objective or 24/7 support commitment.
- Customer responsibilities for contacts, access, lawful data, timely decisions and incident cooperation.
Incident, continuity and exit
- Votegrain investigates suspected incidents, contains affected access where practicable and notifies an affected Customer without undue delay after becoming aware of a personal data breach.
- Supabase provides daily backups with a rolling seven-day availability period. A backup is not a promise of a particular restore point or time for the first pilot.
- The Customer has a 30-day post-term export window. Live Customer Data is deleted through the operator-mediated process within the following 30 days, subject to the DPA's retained-record rules; backups expire on their normal seven-day cycle.
- Customers receive reasonable compliance information and the bounded audit right stated in the DPA.
Customer security responsibilities
- Use individual accounts, protect credentials, enable offered stronger authentication and remove access promptly.
- Assign least-privilege roles, review administrators and billing contacts, and keep participant/export recipients accurate.
- Do not put prohibited sensitive data in free text, custom fields, email, exports or optional AI inputs.
- Protect downloaded files and externally shared links after they leave Votegrain's normal access controls.
- Report suspected compromise through demo@votegrain.com and preserve relevant evidence without attempting unauthorised testing.
Claims and exclusions
Votegrain does not claim a third-party security certification or audit, a customer-controlled encryption key, cryptographic ballot anonymity, uninterrupted service, 24/7 support, a recovery objective, universal immediate session revocation or suitability for a regulated statutory election. The signed Order is the only source of any additional security or service commitment.