Trust Center

Built for procurement-grade evaluation.

Vairity is designed for buyers whose security, compliance, and procurement teams must sign off before code goes near production. This page is the single front door for those reviews — compliance status, sub-processors, data-processing terms, business continuity, and how to reach the right contact on our side of the table.

Need deeper technical posture (architecture, encryption, audit-chain mechanics)? See /security.

Compliance posture

Where we are today — and where we're going.

SOC 2 Type II

In progress. Built to SOC 2 criteria from architecture inception — audit logs, access controls, change management, and availability monitoring all in the platform today.

GDPR & UK GDPR

Ready. Standard Contractual Clauses available. Regional residency options for enterprise deployments. Data-subject rights honored within statutory timelines.

HIPAA

Aligned. PHI-aware workflow templates, BAA-ready deployment patterns. Self-hosted and single-tenant deployments keep PHI in customer-controlled infrastructure.

CCPA / CPRA

Honored. Global Privacy Control and Do Not Track signals respected on the marketing site. Customer data rights governed by the DPA.

ISO 27001

Planned. Control mapping in CONTROL covers ISO 27001 Annex A categories; formal certification on roadmap.

FedRAMP

Oriented. Self-hosted and air-gapped deployment patterns; control-schema mapping in BUILD for public-sector evaluations.

Data residency & deployment

Your data, your perimeter.

Vairity supports self-hosted, single-tenant VPC, and SaaS deployments. For self-hosted and VPC, customer workflow data and AI inputs/outputs remain in customer-controlled infrastructure. For SaaS evaluations, data is isolated by tenant with regional residency options. Specific architecture diagrams and threat models are available under NDA during enterprise evaluation.

Vendor & contract artifacts

The paperwork your procurement team will ask for.

Sub-processor list

A current sub-processor list (email delivery, error monitoring, customer-support tooling, cloud hosting) is shared under NDA during procurement review. We notify customers under contract of material changes.

Request the list →

Data Processing Addendum

The Vairity DPA is available for execution alongside the Customer Agreement. It includes Standard Contractual Clauses, the sub-processor schedule, and security controls aligned to ISO 27001 Annex A.

Request the DPA →

Business continuity & incident response

Documented BCP and incident-response runbooks. Customer notification timelines specified in the DPA. Status communication via direct channel for design-partner customers; status page on roadmap for general availability.

Vulnerability disclosure

We welcome responsible disclosure. Report security issues to contact@vairity.ai. We acknowledge within one business day and coordinate fixes in good faith.

Contact

One inbox for procurement, security review, and compliance questions.

We respond within one business day and route to the right person on our side — engineering for technical posture questions, legal for contract artifacts, the founder for anything strategic.

contact@vairity.ai Technical security posture →