Governance
Compliance
Carrying eighteen billion minutes a year across forty-one jurisdictions means operating under many regulators at once. This page sets out the certifications, controls and obligations that govern how VOLTA runs its network, handles data and admits partners.
ISO 27001
Certified estate
24 mo
Maximum CDR retention
1 hr
Abuse acknowledgement
41
Jurisdictions covered
Licensing and lawful operation
VOLTA operates only where it holds, or its interconnect partner holds, the appropriate authorisation. Lawful interception and data retention obligations are met through nationally approved mediation systems, with access restricted to named, cleared personnel and every request logged for audit.
Data protection by design
Call detail records are pseudonymised after 90 days and deleted at 24 months unless a retention obligation applies. Media is never recorded without explicit contractual instruction. Processing is confined to EU regions unless a partner elects regional residency in Dubai or Singapore under standard contractual clauses.
Fraud and traffic integrity
Real-time engines score every call for Wangiri, IRSF, artificially inflated traffic, CLI spoofing and simbox patterns. Suspicious destinations are blocked at the SBC within seconds and the originating partner is notified with full evidence rather than a silent bill adjustment.
KYC, AML and sanctions
Every counterparty is screened against EU, UN, OFAC and UK consolidated lists at onboarding and continuously thereafter. Ultimate beneficial ownership is verified, and traffic to sanctioned jurisdictions is barred in the routing engine, not merely in policy.
Certifications
Standards and authorisations
Certificates and audit letters are released to partners under NDA through carrier relations.
| Standard | Scope | Notes |
|---|---|---|
| ISO/IEC 27001:2022 | Information security management | Recertified across all nine points of presence, audited annually by an accredited body. |
| ISO 9001:2015 | Quality management | Covers service delivery, incident handling and carrier onboarding processes. |
| GDPR / EU 2016/679 | Data protection | Data protection officer appointed in Riga; records of processing maintained per Article 30. |
| EECC Registration | Electronic communications | Registered electronic communications undertaking in Latvia, notified across the EEA. |
| Ofcom Registration | United Kingdom | General conditions of entitlement compliance including CLI and emergency routing rules. |
| TDRA / IMDA | UAE and Singapore | Regional operating authorisations governing our Dubai and Singapore switching estate. |
Onboarding
Documents required before traffic
Compliance review typically completes within two business days of a complete file. Incomplete packs are the single largest cause of delayed activation.
- Certificate of incorporation and current company extract
- Telecommunications licence or registration in the operating jurisdiction
- VAT number and tax residency confirmation
- Passport or national ID for directors and beneficial owners above 25%
- Proof of registered business address issued within three months
- Bank confirmation letter for settlement account verification
Board oversight
A quarterly risk and compliance committee reviews incidents, audit findings, sanctions exposure and regulatory change. The SVP Regulatory & Compliance reports directly to the board, independent of commercial management.
Independent audit
External penetration testing runs twice yearly against the signalling, portal and API estate. Findings are tracked to closure with remediation targets of 30 days for high severity and 90 days for medium.
Whistleblowing
A confidential reporting channel is available to employees, partners and customers under the EU Whistleblower Directive, with non-retaliation guaranteed and independent triage outside the reporting person's management line.
Abuse handling
The abuse desk operates 24/7 with a one-hour acknowledgement target. Substantiated reports of fraudulent or nuisance traffic result in immediate trunk throttling pending investigation.