SOC 2 Type II
Report available under NDA
Annual audit; latest observation period ended March 2026 with zero exceptions.
all systems operational · status.vaultsecurity.example SOC 2 Type II · ISO 27001 · fictional demo attestations
[ Trust center / Updated July 2026 ]
We are customer zero: our production runs under a dedicated internal Vault tenant, and this page shows what we expect your trust page to show — controls with specifics, attestations with dates, and a disclosure policy with real deadlines.
[ Read first ]
Vault Security, Inc. is a fictional company, and every certification, audit result, and control described on this page is invented demo content — not a real security claim. This page exists to model what a great trust center looks like.
[ Compliance attestations ]
A logo wall proves nothing. Each attestation below carries its status and its honest caveat — including the one still in process.
Report available under NDA
Annual audit; latest observation period ended March 2026 with zero exceptions.
Certified
Certificate covers the platform, corporate IT, and the engineering organization.
BAA available
We sign business associate agreements on Growth tier and above.
SAQ-D attested
As a service provider; attestation of compliance shared under NDA.
In process
Honestly: in process means in process. Agency sponsorship secured; authorization expected 2027. We will not call it 'equivalent' before it is authorized.
DPA available
Standard contractual clauses included; data-residency options on Enterprise.
[ Encryption ]
TLS 1.3 with modern cipher suites on every external and service-to-service connection; TLS 1.2 floor for legacy customer integrations, logged and reported.
AES-256-GCM for all customer data, with envelope encryption via a cloud KMS.
Per-tenant data-encryption keys, rotated every 90 days; key-usage operations are logged and alertable.
Data-classification sampling runs in your cloud region; classified content never leaves your environment — only metadata and match locations do.
[ Access controls ]
The just-in-time elevation workflow we sell is the one our own engineers live under.
SSO with phishing-resistant hardware MFA required for every employee system — no exceptions process exists, deliberately.
No standing production access. Engineers request just-in-time grants that are approved, time-boxed to 4 hours, and fully logged — the same JIT workflow we sell.
Quarterly for all systems, monthly for production and customer-data paths; results feed our own Evidence Engine.
Background checks at hire for all employees; security training at onboarding and annually, with role-specific training for engineers.
[ Audit logging ]
Every administrative and data-access action in your tenant is written to an append-only log retained for 400 days.
Stream your tenant's audit log to your SIEM on Growth tier and above — your security team should not need our permission to watch us.
Our own production is monitored by a dedicated internal Vault tenant. We publish the honest phrase for this: we are customer zero.
[ Vulnerability disclosure policy ]
We run a public vulnerability disclosure program. If you believe you have found a vulnerability in Vault Security, we want to hear from you — and we commit to not pursuing legal action against good-faith research within scope (safe harbor).
Acknowledgement within 2 business days. Triage within 5. Credit given unless you prefer otherwise.
[ Subprocessors ]
| Name | Purpose | Region |
|---|---|---|
| Amazon Web Services | Platform hosting & storage | US / EU (per tenant residency) |
| Postmarker | Transactional email (fictional vendor) | United States |
| Deskflow | Support ticketing (fictional vendor) | United States |
| Cloudlens Analytics | Product usage analytics — no customer security data (fictional vendor) | United States |
| Ledgerline | Billing & invoicing (fictional vendor) | United States |
[ Availability & resilience ]
[ Next step ]
Every demo includes time with a solutions engineer who will answer your security questionnaire line by line — encryption parameters, access reviews, incident SLAs — against this page, not around it.