VorsalOS
HomeSecurity
TRUST CENTER

Security is the product, not a feature.

Vorsal OS is built for organisations that cannot send their data to public AI. Isolation, access control, audit, and sovereign deployment are foundational — not bolted on at the edge.

THE PILLARS

Seven controls, enforced at every layer.

Data isolation

Tenant-isolated by design. Your data never mingles with another customer's and never leaves your boundary.

single-tenantno co-mingling

IP-restricted access

Lock the platform to your networks. Allow-list by IP range, VPN, or private link.

IP allow-listprivate link

Identity & SSO

Enterprise SSO and SCIM provisioning through Entra ID, Google Workspace, and Okta.

SAMLOIDCSCIM

Role-based access

Granular RBAC at every layer — skills, data, agents, workflows, and audit.

RBACleast privilege

Audit logging

Every action, retrieval, and decision is logged, immutable, and exportable to your SIEM.

immutableSIEM export

Encryption

Encrypted at rest and in transit, with customer-managed keys (CMK) and key rotation.

AES-256TLS 1.3CMK

Sovereign deployment

Deploy into a region and jurisdiction you control, including air-gapped environments.

data residencyair-gap
DEPLOYMENT

Runs where your data is allowed to live.

Choose the boundary that satisfies your regulator. The same platform, deployed into the environment you control.

01

VPC

Inside your own virtual private cloud on AWS, Azure, or GCP.

02

Private cloud

A dedicated, single-tenant managed environment.

03

On-premises

In your own data centre, fully under your control.

04

Sovereign region

Pinned to a jurisdiction to satisfy data-residency law.

05

Government cloud

Deployed into accredited government cloud regions.

06

Air-gapped

Disconnected operation for the highest-sensitivity workloads.

IDENTITY

Your identity provider, from day one.

Single sign-on and provisioning through the directories you already run. Access decisions inherit your existing groups and policies.

Microsoft Entra ID
Google Workspace
Okta
COMPLIANCE

An honest compliance posture.

We don't claim certifications we don't yet hold. The architecture and deployment model are the proof today; formal attestations are on the roadmap, and the design is built to drop them in.

SOC 2 Type II

Designed to support

ISO 27001

Designed to support

GDPR

Aligned

HIPAA

Designed to support

// Status reflects current state as of 2026. "Designed to support" means the control environment is built to meet the standard's requirements; formal third-party attestation is in progress and will be published here when complete.

Bring your toughest security questions.

A working session with our security and engineering teams — architecture review, data-handling, deployment topology, and your specific regulatory requirements.