Security at Core

Security isn't an afterthought—it's the foundation of our platform. We implement defense-in-depth strategies to protect your data at every layer.

Self-Serve Trust Center

Compliance Documents

Download the documents your procurement and security teams need to complete vendor review.

Need our SOC 2 Type 1 report (planned — no report exists) or a deeper security review? Contact our team.

SOC 2 Type 1

Planned

GDPR

Self-assessed

CCPA

Self-assessed

HIPAA / BAA

Roadmap

Defense in Depth

Security Measures

Comprehensive protection at every layer of the stack.

Encryption at Rest & Transit

All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Database connections use SSL certificates.

  • AES-256 encryption
  • TLS 1.3
  • SSL database connections
  • Encrypted backups

SOC 2 Type 1 — Planned

A SOC 2 Type 1 audit is planned. No audit firm has been engaged, the audit has not started, and no report date is committed. Internal controls are mapped to the AICPA Trust Service Criteria today — that is preparation, not attestation.

  • Type 1 audit — planned, not started
  • No audit firm engaged; the engagement is still planned
  • Trust Service Criteria mapped — preparation only, no report
  • Type 2 — planned, and blocked until a Type 1 report exists

Infrastructure Security

Deployed on hardened, audited cloud infrastructure with private network isolation, WAF protection, and DDoS mitigation.

  • Private network isolation
  • Web Application Firewall
  • DDoS mitigation
  • Auto-scaling protection

Security Monitoring

Automated infrastructure monitoring with alerting and incident response procedures.

  • Automated monitoring
  • Alert pipelines
  • Incident response plan
  • Log aggregation

Security Testing

First third-party penetration test is scheduled for Q3 2026; continuous automated vulnerability scanning and dependency auditing are in place today. A public bug bounty program is planned for Q4 2026.

  • Continuous automated scanning
  • Dependency auditing
  • Third-party pen test scheduled Q3 2026
  • Public bug bounty Q4 2026

Access Control

Strict access controls with MFA, principle of least privilege, and comprehensive audit logging.

  • MFA required
  • SSO/SAML (roadmap)
  • Role-based access
  • Privileged access management

Internal Practices

Organizational Security

All employees complete security awareness training
Encrypted laptops with endpoint protection
Zero-trust network architecture
Secure software development lifecycle (SDLC)
Regular security reviews and threat modeling
Dependency auditing and automated scanning

Data Processing

We process customer data only as necessary to provide our services. Your data is never used for training AI models or shared with third parties.

  • No data used for AI training
  • Minimal data collection
  • Right to deletion (GDPR/CCPA)

Data Retention

We retain data only as long as necessary to provide services. You can request deletion of your data at any time.

  • Automated data purging
  • 90-day log retention (configurable)
  • Self-service data export

Responsible Disclosure

If you believe you've found a security vulnerability in VAIF Studio, please report it to us immediately. We investigate all reports and respond within 24 hours. We do not pursue legal action against good-faith security researchers.

security@vaif.studio

PGP key available upon request