Security
Live

How Dralvia is built.

This page documents how Dralvia is built, the workspace-isolation boundary, key handling, infrastructure, and the posture we operate under as a live service. We do not claim certifications we have not earned; we describe how the system is shaped today.

✓Per-workspace isolation✓Rotatable API keys✓No SOC 2 claim (yet)
Product preview

Workspace overview

See Dralvia in action.

The dashboard brings protection modules, recent activity, charts, queues, and global scan context into one workspace.

  • Start from one operational overview
  • Open the relevant workflow
  • See clear setup messages when a connection or configuration is needed

This preview shows the Dralvia workspace. Sign in to see your own scans, alerts, and activity.

Dralvia Dralvia Platform workspace preview
Product preview · Dralvia Platform
Architecture

Workspace isolation is the spine.

Logical isolation per workspace

Every verdict, EvidencePack, monitor target, and API key is scoped to a workspace; cross-workspace access is structurally prevented at the request and storage layers.

Authentication

OAuth / session for the dashboard; bearer-token API keys per workspace, shown once at creation, stored hashed, and rotatable from the console.

Cross-workspace operator access (opt-in)

For MSPs and consulting firms, an operator account can be granted explicit, revocable access across workspaces, per role.

Data at rest

Encrypted at rest by the cloud provider (AES-256). Per-workspace EvidencePack storage scoped to the workspace.

Data in transit

TLS 1.2+ on all public endpoints; internal service-to-service traffic over a private network with short-lived signed tokens.

Secret handling

API keys hashed at rest. Third-party engine credentials are stored in a managed secret store, never in code, and never exposed via customer-facing APIs.

For your security team

What to review before you buy.

Data scope and retention

Every verdict, EvidencePack, and key is scoped to your workspace, and we collect the minimum needed to run a scan. The Data handling page lists what each scanner stores and for how long.

Sub-processors and hosting

Our sub-processor list and hosting providers are published and kept current on the Sub-processors page.

Encryption and secrets

AES-256 at rest, TLS 1.2+ in transit, API keys hashed, and third-party engine credentials in a managed secret store, never in code or customer-facing APIs.

Access and isolation

Per-workspace logical isolation enforced at the request and storage layers; cross-workspace operator access is explicit, revocable, and per role.

Vulnerability disclosure

A published responsible-disclosure channel with a security contact ([email protected]).

Legal terms

The DPA, sub-processor list, and breach-notification terms are documented for your review. Ask us for the current versions.

FAQ

Honest answers.

None of these certifications are in force yet, and we will not display the badges until they are. Talk to us if a specific certification is a hard requirement, it informs our priority order.

Questions about our security?

Read the trust center, or report a vulnerability through responsible disclosure.