Company/Trust

Plain trust.
Not a sales PDF.

What is true today, including what we do not have. Updated when something changes, not on a marketing calendar.

None
Certifications held
No SOC 2, ISO 27001 or other third-party attestation today.
India
Data location
Hosted on infrastructure we operate; self-hosted anywhere.
1
Third-party subprocessor
Cloudflare at the network edge. Everything else is first-party.
Yes
DPA available
Standard data-processing agreement on request.
What we hold, and what we do not

Plainly.

We hold
Findings and their typed evidence, SBOM components, entity and relationship rows, audit events, encrypted integration credentials, user accounts and session metadata.
We do not hold
Your repositories after a scan completes, your cloud credentials in plain text, or any customer data outside the region you deploy in. With a customer-registered execution cluster, code never leaves your network.
Certifications
None. SecurityVault maps your controls to frameworks; it holds no third-party certification of its own today. We will say so on this page the day that changes.
Questionnaires
CAIQ, SIG and custom questionnaires answered on request; our security architecture document is shared under NDA.
Contracts
MSA, DPA and the subprocessor list. The contracting entity is SecurityVault Systems Private Limited, India.
Commitments

Five we make. Each enforced by code.

01

Scanners never hold platform credentials

Enforced by the split-secret Job specification and a CI banned-pattern gate.

02

Tenant scope in every query

Row-level policies asserted in CI; handler-level checks gated at review.

03

No machine writes to dispositions

ORM guard plus database trigger. Reason codes mandatory.

04

Fail closed

Evaluator error is a deny; unsigned callback is a reject.

05

We tell you what is missing

Lineage gaps carry a reason; this page lists what we do not have.

06

Disclosure honoured

security.txt published; acknowledgement within two business days.

Who to talk to

Direct lines.

Everything else
Need the details

Ask for the architecture and the DPA.

We share the security architecture document under NDA and answer questionnaires from the same source of truth.