How Dralvia is built.
This page documents how Dralvia is built, the workspace-isolation boundary, key handling, infrastructure, and the posture we operate under as a live service. We do not claim certifications we have not earned; we describe how the system is shaped today.
Workspace overview
See Dralvia in action.
The dashboard brings protection modules, recent activity, charts, queues, and global scan context into one workspace.
- Start from one operational overview
- Open the relevant workflow
- See clear setup messages when a connection or configuration is needed
This preview shows the Dralvia workspace. Sign in to see your own scans, alerts, and activity.

Workspace isolation is the spine.
Logical isolation per workspace
Every verdict, EvidencePack, monitor target, and API key is scoped to a workspace; cross-workspace access is structurally prevented at the request and storage layers.
Authentication
OAuth / session for the dashboard; bearer-token API keys per workspace, shown once at creation, stored hashed, and rotatable from the console.
Cross-workspace operator access (opt-in)
For MSPs and consulting firms, an operator account can be granted explicit, revocable access across workspaces, per role.
Data at rest
Encrypted at rest by the cloud provider (AES-256). Per-workspace EvidencePack storage scoped to the workspace.
Data in transit
TLS 1.2+ on all public endpoints; internal service-to-service traffic over a private network with short-lived signed tokens.
Secret handling
API keys hashed at rest. Third-party engine credentials are stored in a managed secret store, never in code, and never exposed via customer-facing APIs.
What to review before you buy.
Data scope and retention
Every verdict, EvidencePack, and key is scoped to your workspace, and we collect the minimum needed to run a scan. The Data handling page lists what each scanner stores and for how long.
Sub-processors and hosting
Our sub-processor list and hosting providers are published and kept current on the Sub-processors page.
Encryption and secrets
AES-256 at rest, TLS 1.2+ in transit, API keys hashed, and third-party engine credentials in a managed secret store, never in code or customer-facing APIs.
Access and isolation
Per-workspace logical isolation enforced at the request and storage layers; cross-workspace operator access is explicit, revocable, and per role.
Vulnerability disclosure
A published responsible-disclosure channel with a security contact ([email protected]).
Legal terms
The DPA, sub-processor list, and breach-notification terms are documented for your review. Ask us for the current versions.
Honest answers.
None of these certifications are in force yet, and we will not display the badges until they are. Talk to us if a specific certification is a hard requirement, it informs our priority order.
Questions about our security?
Read the trust center, or report a vulnerability through responsible disclosure.