The specification we hold ourselves to
Every line below is something we can document and hand to your auditors — not a marketing claim. Followed by the process every engagement runs through, our incident response commitment, and what current clients say after the first quarter.
Infrastructure & process, line by line
- Encryption standard
- WireGuard and OpenVPN tunnels secured with AES-256-GCM and perfect forward secrecy on every gateway, audited annually by an independent third party.
- Logging policy
- A verified zero-log architecture across all VPN and privacy-relay nodes — no connection logs, no traffic logs, no DNS query retention.
- Global footprint
- 312 active nodes across 54 countries, delivered through seven infrastructure and cloud partners so no single provider outage takes your access down.
- Monitoring & response
- A 24/7/365 security operations center with a 15-minute acknowledgment SLA on critical alerts, backed by the same predictive models sold as a standalone service.
- Compliance alignment
- Internal practices and client deliverables mapped to ISO/IEC 27001, SOC 2 Type II and GDPR control families, with documentation ready for your auditors.
- Device hardening
- GrapheneOS fleet imaging with remote attestation, so a lost or seized device can be verified — not just remotely wiped.
- Engagement model
- A named technical account manager and a quarterly risk review for every Professional and Sovereign client — no ticket queues for strategic conversations.
- Data residency
- Telemetry and model training data stay within an agreed region by default; cross-region processing requires a separate signed data-processing agreement.
- Penetration testing
- An independent third party tests our own network and application layers twice yearly; findings and remediation timelines are available to Sovereign clients on request.
- Access control
- Least-privilege access to client environments, individually logged and reviewed quarterly; no shared administrative credentials across engineers.
- Business continuity
- Automatic node failover within the same region in under four seconds, with SOC coverage split across our Austin and Gandhinagar offices so no single office outage affects monitoring.
- Sub-processor transparency
- A current list of infrastructure sub-processors (AWS, Azure, Google Cloud, Oracle Cloud, Cloudflare, DigitalOcean) is available on request and updated before any new provider is added.
- Breach notification commitment
- Any confirmed incident affecting client data is disclosed within 72 hours of confirmation, in writing, regardless of what a specific contract's minimum requires.
Four phases, from assessment to a monitored environment
The same process whether you’re leasing a handful of VPN nodes or standing up a full risk architecture program.
Map what exists today
We inventory current infrastructure, identities, vendors and device fleets, and identify where exposure is highest. Typically one to two weeks, ending in a written findings summary.
Design the target state
A risk architecture review and network design tailored to your regulatory footprint, headcount and threat model, reviewed with your engineering leads before anything is built.
Stand up the environment
VPN gateways provisioned, AI models tuned to your telemetry, and GrapheneOS fleets imaged and enrolled — on a schedule agreed up front, not an open-ended rollout.
Operate and review
24/7 monitoring from our SOC, with quarterly reviews to adjust the architecture as your company changes — the relationship that continues for the life of the contract.
Our incident response commitment
The same four steps every time, whether the trigger is one of our own predictive alerts or something you report to us directly.
Acknowledge within 15 minutes
Critical alerts — whether raised by our monitoring or reported by you — are acknowledged by a SOC engineer within 15 minutes, 24/7.
Isolate before investigating
Affected nodes or accounts are isolated first to stop active exposure, then investigated — we don't wait for root cause before limiting the blast radius.
Disclose within 72 hours
Any confirmed incident affecting client data is disclosed in writing within 72 hours of confirmation, with what we know and don't yet know clearly separated.
Written post-incident report
A written after-action report follows every incident — timeline, root cause, and the specific architecture change made to prevent a repeat.
What operating teams say after the first quarter
We consolidated four vendors into one. The quarterly risk review alone has been worth the contract — it’s the first time infrastructure and security advice has come from the same room.
The GrapheneOS rollout for our field team took nine days end to end, including MDM policy design. Support has been direct engineers, not a ticket queue.
Their predictive model flagged a credential-stuffing pattern two weeks before it would have shown up in our SIEM’s standard rules. That lead time mattered.
Procurement asked for our sub-processor list and pen-test summary the same week we signed. Having it ready without a scramble said more about them than any pitch deck did.
We had an actual incident in month four — a misconfigured access rule, nobody's fault of ours. The 72-hour disclosure and the post-incident report were more thorough than I expected.
The risk architecture review found a vendor with far broader access than we realized we’d granted. That alone justified the engagement before the VPN migration even started.
Want the compliance documentation for your auditors?
We’ll walk your security or procurement team through the full control mapping.