Security at Voder
Last updated:
At a glance
Voder is designed to read Xero data, not change accounting records. It does not retain Xero financial figures. It stores limited account and service data, including an encrypted Xero connection token.
No online service can promise zero risk. This page explains the controls Voder uses and the evidence limits that still apply.
Read-only Xero access
Voder requests read-only Xero accounting permissions. It can retrieve accounting information to answer a question, but it cannot create, change, or delete accounting records in Xero.
Voder fetches only the information needed for the request. It discards the financial figures after returning the requested information to the AI assistant selected by the customer.
Account and organisation access
Voder uses passwordless sign-in. Sign-in codes are stored only as hashes. They are single-use, expire after 15 minutes, and stop working after repeated incorrect attempts.
Before showing or using an organisation, Voder checks that the signed-in account has access to it. Sensitive organisation actions, such as disconnecting Xero, are restricted to the organisation owner.
Encryption and hosting
Voder encrypts Xero connection tokens using AES-256-GCM, a standard encryption method. Each stored token has an encryption key protected by Google Cloud Key Management Service. The service account that runs Voder can use the key. The service account that deploys Voder cannot.
Voder’s primary database and encryption key are in Australia. Its production application service currently runs in Google Cloud’s Singapore region.
What Voder stores and for how long
Voder stores limited account and service records. These include an email address, organisation access records, an encrypted Xero connection token, feedback a customer chooses to send, and limited billing records for subscribers. Voder does not store full card numbers.
Voder retains and deletes data as follows:
- Hashed sign-in codes are deleted automatically 15 minutes after issue.
- Signed-in sessions expire after 7 days.
- Normal token retention: Voder keeps an encrypted Xero connection token while the connection is available.
- Confirmed token removal: Voder removes the token after disconnection, account deletion, or the end of paid access once Xero confirms that the connection was removed.
- If token removal is not confirmed: Voder blocks access and keeps the encrypted token only for a limited retry period.
- Email and account records are deleted when the customer asks Voder to delete the account.
- Feedback is deleted on request.
- Limited billing records may be retained for tax, accounting, fraud, dispute, and legal obligations.
- Technical logs are kept for up to 30 days, then automatically deleted.
Read the full retention and deletion schedule in Voder’s Privacy Policy.
Logs
Technical logs record which tool ran, parameter names and lengths, whether the request succeeded, and how long it took. They do not contain parameter values or Xero financial figures.
Service providers and AI
Voder relies on a small set of service providers:
- Google Cloud provides application infrastructure and the database.
- Resend sends sign-in email.
- Xero is the source of accounting data.
- Stripe provides subscription checkout and billing.
- The AI assistant selected by the customer can receive information returned by Voder.
Voder and Windy Road do not train or fine-tune AI models using Xero API data or other customer data.
The customer selects the AI assistant. The AI provider handles prompts and information returned by Voder under its own terms, privacy policy, and account settings.
Voder does not sell customer data or share it for advertising.
Security assessment and current limits
Voder completed an internal, self-driven security assessment and penetration test in August 2026. The assessment began in May 2026 and closed with residual findings. Remediation of those findings is ongoing.
This was not an independent or third-party assessment. Voder does not currently claim SOC 2 or ISO 27001 certification, zero risk, or that security incidents cannot happen.
Report a security issue
Email security@voder.ai. Please do not file a public issue for a vulnerability.
Voder aims to:
- Acknowledge a report within 7 calendar days.
- Provide an initial assessment within 14 days.
- Fix confirmed vulnerabilities within 90 days.