Specification

Infrastructure & process, line by line

Encryption standard
WireGuard and OpenVPN tunnels secured with AES-256-GCM and perfect forward secrecy on every gateway, audited annually by an independent third party.
Logging policy
A verified zero-log architecture across all VPN and privacy-relay nodes — no connection logs, no traffic logs, no DNS query retention.
Global footprint
312 active nodes across 54 countries, delivered through seven infrastructure and cloud partners so no single provider outage takes your access down.
Monitoring & response
A 24/7/365 security operations center with a 15-minute acknowledgment SLA on critical alerts, backed by the same predictive models sold as a standalone service.
Compliance alignment
Internal practices and client deliverables mapped to ISO/IEC 27001, SOC 2 Type II and GDPR control families, with documentation ready for your auditors.
Device hardening
GrapheneOS fleet imaging with remote attestation, so a lost or seized device can be verified — not just remotely wiped.
Engagement model
A named technical account manager and a quarterly risk review for every Professional and Sovereign client — no ticket queues for strategic conversations.
Data residency
Telemetry and model training data stay within an agreed region by default; cross-region processing requires a separate signed data-processing agreement.
Penetration testing
An independent third party tests our own network and application layers twice yearly; findings and remediation timelines are available to Sovereign clients on request.
Access control
Least-privilege access to client environments, individually logged and reviewed quarterly; no shared administrative credentials across engineers.
Business continuity
Automatic node failover within the same region in under four seconds, with SOC coverage split across our Austin and Gandhinagar offices so no single office outage affects monitoring.
Sub-processor transparency
A current list of infrastructure sub-processors (AWS, Azure, Google Cloud, Oracle Cloud, Cloudflare, DigitalOcean) is available on request and updated before any new provider is added.
Breach notification commitment
Any confirmed incident affecting client data is disclosed within 72 hours of confirmation, in writing, regardless of what a specific contract's minimum requires.
How we deploy

Four phases, from assessment to a monitored environment

The same process whether you’re leasing a handful of VPN nodes or standing up a full risk architecture program.

PHASE 01 — Assessment

Map what exists today

We inventory current infrastructure, identities, vendors and device fleets, and identify where exposure is highest. Typically one to two weeks, ending in a written findings summary.

PHASE 02 — Architecture

Design the target state

A risk architecture review and network design tailored to your regulatory footprint, headcount and threat model, reviewed with your engineering leads before anything is built.

PHASE 03 — Deployment

Stand up the environment

VPN gateways provisioned, AI models tuned to your telemetry, and GrapheneOS fleets imaged and enrolled — on a schedule agreed up front, not an open-ended rollout.

PHASE 04 — Monitoring

Operate and review

24/7 monitoring from our SOC, with quarterly reviews to adjust the architecture as your company changes — the relationship that continues for the life of the contract.

If something goes wrong

Our incident response commitment

The same four steps every time, whether the trigger is one of our own predictive alerts or something you report to us directly.

STEP 01 — Detect

Acknowledge within 15 minutes

Critical alerts — whether raised by our monitoring or reported by you — are acknowledged by a SOC engineer within 15 minutes, 24/7.

STEP 02 — Contain

Isolate before investigating

Affected nodes or accounts are isolated first to stop active exposure, then investigated — we don't wait for root cause before limiting the blast radius.

STEP 03 — Notify

Disclose within 72 hours

Any confirmed incident affecting client data is disclosed in writing within 72 hours of confirmation, with what we know and don't yet know clearly separated.

STEP 04 — Review

Written post-incident report

A written after-action report follows every incident — timeline, root cause, and the specific architecture change made to prevent a repeat.

From current clients

What operating teams say after the first quarter

We consolidated four vendors into one. The quarterly risk review alone has been worth the contract — it’s the first time infrastructure and security advice has come from the same room.
VP of InfrastructureMid-market fintech, EU
The GrapheneOS rollout for our field team took nine days end to end, including MDM policy design. Support has been direct engineers, not a ticket queue.
Director of IT SecurityLogistics group, APAC
Their predictive model flagged a credential-stuffing pattern two weeks before it would have shown up in our SIEM’s standard rules. That lead time mattered.
Head of Security OperationsB2B SaaS, North America
Procurement asked for our sub-processor list and pen-test summary the same week we signed. Having it ready without a scramble said more about them than any pitch deck did.
General CounselHealthcare technology, US
We had an actual incident in month four — a misconfigured access rule, nobody's fault of ours. The 72-hour disclosure and the post-incident report were more thorough than I expected.
CTOSeries B SaaS, North America
The risk architecture review found a vendor with far broader access than we realized we’d granted. That alone justified the engagement before the VPN migration even started.
Head of Platform EngineeringLegal services, UK

Want the compliance documentation for your auditors?

We’ll walk your security or procurement team through the full control mapping.