Security

Last updated: October 6, 2026

volAgent serves institutional desks, so access is scoped, checked on every request and kept within each firm. This page summarises how; your firm's agreement may add detail.

Keys and access

Your data stays with your firm

Firm-private data and settings are served only to keys of that firm. Shared market analytics are the same for every customer and carry no other firm's information.

Your Claude key

If you register a Claude API key for query jobs, it is sent once over HTTPS, stored encrypted in a key vault and used only to run your firm's jobs. It is never shown again, never logged and never placed in a URL. You can replace or remove it at any time.

This site

In transit

All traffic to the volAgent gateway uses HTTPS.

Reporting a security issue

If you believe you have found a vulnerability, contact us through volfront.com, with the request id where you have one. Please do not access data that is not yours, and give us reasonable time to fix the issue before disclosing it. We will acknowledge your report and keep you updated.

If a key is exposed

Contact us through volfront.com and we will revoke it and issue a replacement.