Security
Last updated: October 6, 2026
volAgent serves institutional desks, so access is scoped, checked on every request and kept within each firm. This page summarises how; your firm's agreement may add detail.
Keys and access
- Every request carries a volAgent key issued to your firm. Keys are checked on every request and can be revoked at once.
- Each key is scoped to the products it may use (Excel, REST, datasets, MCP, jobs), and each firm sees only what it is entitled to.
- MCP access uses keys issued for AI hosts. Requests are rate-limited and count against per-key and per-firm quotas, and repeated failed sign-ins are throttled.
- Every response carries a request id, so any call can be traced when you contact us.
Your data stays with your firm
Firm-private data and settings are served only to keys of that firm. Shared market analytics are the same for every customer and carry no other firm's information.
Your Claude key
If you register a Claude API key for query jobs, it is sent once over HTTPS, stored encrypted in a key vault and used only to run your firm's jobs. It is never shown again, never logged and never placed in a URL. You can replace or remove it at any time.
This site
- This is a static site with no server-side accounts. It sets no cookies of its own and loads no analytics.
- A strict content security policy allows scripts from this site and, for the request-access form, from Cloudflare's verification service. Fonts load from Google Fonts.
- The request-access form is checked by Cloudflare Turnstile and sent over HTTPS to a Cloudflare service that validates it again and emails our team.
- Your volAgent key stays in your browser and goes only to the gateway you configure, over HTTPS. Generated code shows a placeholder unless you choose to insert your key.
- The Claude key field is cleared the moment you submit it.
In transit
All traffic to the volAgent gateway uses HTTPS.
Reporting a security issue
If you believe you have found a vulnerability, contact us through volfront.com, with the request id where you have one. Please do not access data that is not yours, and give us reasonable time to fix the issue before disclosing it. We will acknowledge your report and keep you updated.
If a key is exposed
Contact us through volfront.com and we will revoke it and issue a replacement.