Security at Voder

Last updated:

At a glance

Voder is designed to read Xero data, not change accounting records. It does not retain Xero financial figures. It stores limited account and service data, including an encrypted Xero connection token.

No online service can promise zero risk. This page explains the controls Voder uses and the evidence limits that still apply.

Read-only Xero access

Voder requests read-only Xero accounting permissions. It can retrieve accounting information to answer a question, but it cannot create, change, or delete accounting records in Xero.

Voder fetches only the information needed for the request. It discards the financial figures after returning the requested information to the AI assistant selected by the customer.

Account and organisation access

Voder uses passwordless sign-in. Sign-in codes are stored only as hashes. They are single-use, expire after 15 minutes, and stop working after repeated incorrect attempts.

Before showing or using an organisation, Voder checks that the signed-in account has access to it. Sensitive organisation actions, such as disconnecting Xero, are restricted to the organisation owner.

Encryption and hosting

Voder encrypts Xero connection tokens using AES-256-GCM, a standard encryption method. Each stored token has an encryption key protected by Google Cloud Key Management Service. The service account that runs Voder can use the key. The service account that deploys Voder cannot.

Voder’s primary database and encryption key are in Australia. Its production application service currently runs in Google Cloud’s Singapore region.

What Voder stores and for how long

Voder stores limited account and service records. These include an email address, organisation access records, an encrypted Xero connection token, feedback a customer chooses to send, and limited billing records for subscribers. Voder does not store full card numbers.

Voder retains and deletes data as follows:

Read the full retention and deletion schedule in Voder’s Privacy Policy.

Logs

Technical logs record which tool ran, parameter names and lengths, whether the request succeeded, and how long it took. They do not contain parameter values or Xero financial figures.

Service providers and AI

Voder relies on a small set of service providers:

Voder and Windy Road do not train or fine-tune AI models using Xero API data or other customer data.

The customer selects the AI assistant. The AI provider handles prompts and information returned by Voder under its own terms, privacy policy, and account settings.

Voder does not sell customer data or share it for advertising.

Security assessment and current limits

Voder completed an internal, self-driven security assessment and penetration test in August 2026. The assessment began in May 2026 and closed with residual findings. Remediation of those findings is ongoing.

This was not an independent or third-party assessment. Voder does not currently claim SOC 2 or ISO 27001 certification, zero risk, or that security incidents cannot happen.

Report a security issue

Email security@voder.ai. Please do not file a public issue for a vulnerability.

Voder aims to:

More information

Back to home