Skip to main content

all systems operational · status.vaultsecurity.example SOC 2 Type II · ISO 27001 · fictional demo attestations

VAULT SECURITY
Request a demo

[ Trust center / Updated July 2026 ]

Our own security posture, in the open

We are customer zero: our production runs under a dedicated internal Vault tenant, and this page shows what we expect your trust page to show — controls with specifics, attestations with dates, and a disclosure policy with real deadlines.

[ Read first ]

Vault Security, Inc. is a fictional company, and every certification, audit result, and control described on this page is invented demo content — not a real security claim. This page exists to model what a great trust center looks like.

[ Compliance attestations ]

Certifications with dates, not badges

A logo wall proves nothing. Each attestation below carries its status and its honest caveat — including the one still in process.

SOC 2 Type II

Report available under NDA

Annual audit; latest observation period ended March 2026 with zero exceptions.

ISO/IEC 27001:2022

Certified

Certificate covers the platform, corporate IT, and the engineering organization.

HIPAA

BAA available

We sign business associate agreements on Growth tier and above.

PCI DSS 4.0

SAQ-D attested

As a service provider; attestation of compliance shared under NDA.

FedRAMP Moderate

In process

Honestly: in process means in process. Agency sponsorship secured; authorization expected 2027. We will not call it 'equivalent' before it is authorized.

GDPR / CCPA

DPA available

Standard contractual clauses included; data-residency options on Enterprise.

[ Encryption ]

Encryption, with the parameters stated

In transit

TLS 1.3 with modern cipher suites on every external and service-to-service connection; TLS 1.2 floor for legacy customer integrations, logged and reported.

At rest

AES-256-GCM for all customer data, with envelope encryption via a cloud KMS.

Key management

Per-tenant data-encryption keys, rotated every 90 days; key-usage operations are logged and alertable.

Scoped scanning

Data-classification sampling runs in your cloud region; classified content never leaves your environment — only metadata and match locations do.

[ Access controls ]

No standing production access — for us either

The just-in-time elevation workflow we sell is the one our own engineers live under.

Workforce authentication

SSO with phishing-resistant hardware MFA required for every employee system — no exceptions process exists, deliberately.

Production access

No standing production access. Engineers request just-in-time grants that are approved, time-boxed to 4 hours, and fully logged — the same JIT workflow we sell.

Access reviews

Quarterly for all systems, monthly for production and customer-data paths; results feed our own Evidence Engine.

Personnel

Background checks at hire for all employees; security training at onboarding and annually, with role-specific training for engineers.

[ Audit logging ]

Watch us watching your tenant

Immutable platform audit log

Every administrative and data-access action in your tenant is written to an append-only log retained for 400 days.

Customer-exportable

Stream your tenant's audit log to your SIEM on Growth tier and above — your security team should not need our permission to watch us.

Internal monitoring

Our own production is monitored by a dedicated internal Vault tenant. We publish the honest phrase for this: we are customer zero.

[ Vulnerability disclosure policy ]

Found something? Good — tell us.

We run a public vulnerability disclosure program. If you believe you have found a vulnerability in Vault Security, we want to hear from you — and we commit to not pursuing legal action against good-faith research within scope (safe harbor).

  • In scope: the Vault platform, public APIs, and this website
  • Out of scope: social engineering, physical attacks, denial of service, and third-party services we do not operate
  • Report to security@vaultsecurity.example — PGP key published at /.well-known/security.txt
  • We acknowledge reports within 2 business days and aim to triage within 5
  • Coordinated disclosure after a fix ships, or 90 days, whichever is sooner — researchers are credited unless they prefer otherwise

Report a vulnerability

Remediation SLAs

Critical
Remediation target: 5 days
High
Remediation target: 30 days
Medium
Remediation target: 90 days
Low
Best effort — next scheduled release

Acknowledgement within 2 business days. Triage within 5. Credit given unless you prefer otherwise.

[ Subprocessors ]

Who touches customer data, and why

Subprocessors with access to customer data — fictional list, updated July 2026. Customers receive 30 days' advance notice before any addition or change.
Name Purpose Region
Amazon Web Services Platform hosting & storage US / EU (per tenant residency)
Postmarker Transactional email (fictional vendor) United States
Deskflow Support ticketing (fictional vendor) United States
Cloudlens Analytics Product usage analytics — no customer security data (fictional vendor) United States
Ledgerline Billing & invoicing (fictional vendor) United States

[ Availability & resilience ]

Uptime commitments, in writing

Uptime SLA
99.95% monthly uptime SLA on Scale and Enterprise; 99.9% on Core and Growth
Status page
status.vaultsecurity.example — live status page with 12-month incident history
Recovery time
Recovery time objective: 4 hours
Recovery point
Recovery point objective: 15 minutes

[ Next step ]

Ask us the hard questions

Every demo includes time with a solutions engineer who will answer your security questionnaire line by line — encryption parameters, access reviews, incident SLAs — against this page, not around it.

Sample site by SearchPod