Trust Center

We build Vallorix to the standards it helps you meet.

Vallorix is a compliance platform, so security isn't a feature bolted on — it's the product. Here's how we secure Vallorix, and how our own program runs on Vallorix itself.

Our compliance program runs on Vallorix

Vallorix is self-hosted on Inferix sovereign infrastructure, and Inferix runs its own SOC 2 and HIPAA program on Vallorix. We use the same continuous-evidence engine, the same controls, and the same auditor evidence room we give you — so our posture is always current, not a once-a-year snapshot.

  • Self-hosted — no third-party review platform holds our evidence
  • Self-hosted — your security team can inspect the deployment, not a black box
  • Sovereign hosting — data resident where it should be
Self-hostedevidence in-boundary
Privateyour deployment
SovereignInferix infrastructure
Security practices

How Vallorix is secured

The controls behind the platform — the same categories Vallorix helps you evidence.

Data

Encryption

Data encrypted in transit (TLS 1.2+) and at rest. Secrets are managed with a dedicated encryption key, never checked into source.

Access

Access control

Role-based access control, least-privilege by default, SSO/SAML for teams, and full audit logging of privileged actions.

Isolation

Tenant isolation

Organization-scoped data isolation is enforced in the platform, with server-side authorization on every request — and covered by end-to-end tests.

Network

Hardened by default

SSRF protections, strict security headers and CSP, and outbound controls. The app runs least-privilege in a hardened container.

Resilience

Vulnerability management

Dependencies are pinned and monitored, images are rebuilt from a pinned base, and the agent verifies release signatures on update.

Privacy

PII-free logging

Logs are designed to exclude personal and sensitive data, so operational telemetry never becomes a data-exposure risk.

Frameworks

What we build to

Vallorix is architected to these frameworks. Formal certification is issued by accredited third-party auditors; where a program is in progress we say so plainly.

Architected to

SOC 2

Controls mapped to the Trust Services Criteria; continuous evidence collected in-platform. Program in progress.

Architected to

ISO 27001

ISMS scaffolding, Annex A mapping and risk treatment operated continuously. Program in progress.

Supported

HIPAA

Administrative, physical and technical safeguards with BAA tracking, for deployments handling PHI.

We don't display certification badges we haven't earned. When our audits complete, the reports will be available here on request.

Subprocessors

A short list, by design

Because Vallorix is self-hosted, most deployments have no third-party data processors. For our own managed instances:

Subprocessor
Purpose
Data
Inferix
Sovereign compute & hosting
Platform
Your own infrastructure
Self-hosted deployments
All

Self-host Vallorix and this list is yours to define — your evidence never touches a vendor you didn't choose.

FAQ

Trust & security questions

Is Vallorix itself SOC 2 certified?+
We build Vallorix to SOC 2 and run our program on Vallorix continuously, but certification is issued by an accredited third-party auditor and our program is in progress. We won't display a badge we haven't earned — when reports are available, you can request them here.
Where does my data live?+
Wherever you deploy Vallorix. It's self-hosted, so your evidence, documents and audit data stay inside your own infrastructure and region. For our managed instances, hosting is on Inferix sovereign infrastructure in the region you choose.
How is Vallorix transparent?+
Vallorix runs on your own infrastructure, so your security and compliance teams can inspect exactly how it is deployed and how your data is handled — nothing hidden in a vendor cloud.
How do I report a security issue?+
Reach us through the demo/contact form and mark it security. We take responsible disclosure seriously and will respond promptly.

Want our security documentation?

Request our security overview, subprocessor list, and program status — or spin up Vallorix on your own infrastructure and own the whole boundary.

V
Vallorix AssistantAI · answers about compliance & the product
AI assistant · not a human · answers may be imperfect