Vallorix is a compliance platform, so security isn't a feature bolted on — it's the product. Here's how we secure Vallorix, and how our own program runs on Vallorix itself.
Vallorix is self-hosted on Inferix sovereign infrastructure, and Inferix runs its own SOC 2 and HIPAA program on Vallorix. We use the same continuous-evidence engine, the same controls, and the same auditor evidence room we give you — so our posture is always current, not a once-a-year snapshot.
The controls behind the platform — the same categories Vallorix helps you evidence.
Data encrypted in transit (TLS 1.2+) and at rest. Secrets are managed with a dedicated encryption key, never checked into source.
Role-based access control, least-privilege by default, SSO/SAML for teams, and full audit logging of privileged actions.
Organization-scoped data isolation is enforced in the platform, with server-side authorization on every request — and covered by end-to-end tests.
SSRF protections, strict security headers and CSP, and outbound controls. The app runs least-privilege in a hardened container.
Dependencies are pinned and monitored, images are rebuilt from a pinned base, and the agent verifies release signatures on update.
Logs are designed to exclude personal and sensitive data, so operational telemetry never becomes a data-exposure risk.
Vallorix is architected to these frameworks. Formal certification is issued by accredited third-party auditors; where a program is in progress we say so plainly.
Controls mapped to the Trust Services Criteria; continuous evidence collected in-platform. Program in progress.
ISMS scaffolding, Annex A mapping and risk treatment operated continuously. Program in progress.
Administrative, physical and technical safeguards with BAA tracking, for deployments handling PHI.
We don't display certification badges we haven't earned. When our audits complete, the reports will be available here on request.
Because Vallorix is self-hosted, most deployments have no third-party data processors. For our own managed instances:
Self-host Vallorix and this list is yours to define — your evidence never touches a vendor you didn't choose.
Request our security overview, subprocessor list, and program status — or spin up Vallorix on your own infrastructure and own the whole boundary.