Trust & security

One public trust surface for contact paths, legal posture, evidence model, and deployment reality.

This page is the public checkpoint for how Dralvia handles security reporting, company/legal visibility, evidence backed outputs, and deployment expectations during the current launch readiness phase.

It is intentionally static and repo backed so the trust surface stays available even when the product runtime is under maintenance or a live API surface is degraded.

What this page covers

Public contact matrix for support, security, and legal requests.
Link map to legal notice, privacy, terms, cookies, DPA, and subprocessors.
Public explanation of EvidencePacks, transparency logs, and validation expectations.
Current hosted, self-hosted, and enterprise deployment posture.

Support

Use the support mailbox for blocking product issues, onboarding questions, and operational follow up.

[email protected]

Security disclosures

Report vulnerabilities, active abuse, or suspicious security behavior through the security contact.

[email protected]

Legal and privacy

Route privacy, DPA, subprocessor, and legal-notice questions through the legal contact.

[email protected]

Vendor security review

The answers to your security questionnaire, on one page.

If your team sends a vendor security questionnaire, these are the common answers up front, with a link to the detail for each. Send this page to your security reviewer to skip the back and forth.

Where is data hosted, and how long is it kept?

Primary hosting is in the EEA. Each scanner keeps only what it needs, with per-scanner retention spelled out, and customers can run self-hosted for full local control of storage.

Data handling and retention

How do you safely scan malicious URLs and files?

Live malicious content is opened only inside network-isolated sandboxes that have no route to our internal systems or datastores. Their only outbound path is a filtered gateway that blocks private and internal network addresses, and each runs under strict CPU, memory, and process limits.

How Dralvia is built

How is customer data isolated and protected?

Per-workspace isolation with scoped API keys and role-based access. Traffic is served over TLS, and scan inputs/outputs are tied to the workspace that created them.

Architecture and isolation

Who are your subprocessors?

The current infrastructure and delivery subprocessors are published and kept up to date as a crawlable list.

Subprocessor inventory

How do we report a vulnerability or incident?

A published responsible-disclosure path plus a machine-readable security.txt, monitored by the security contact.

Responsible disclosure

How do you handle data processing agreements?

A DPA overview describes the processor posture, transfer model, and contract expectations for buyers who need a signed agreement.

DPA overview

What is your compliance posture today?

We do not claim certifications we do not hold. Instead, this trust surface gives you the underlying evidence: architecture, data handling, subprocessors, disclosure, and signed EvidencePack records for audit.

What ships today

Evidence model

Trust in Dralvia comes from recorded evidence, not only verdict labels.

EvidencePack exports

Dralvia records signed EvidencePack artifacts so customers can keep the scan inputs, outputs, and reasoning chain together for incident handling and audit work.

Transparency log verification

Where transparency logging is enabled, EvidencePack hashes and timestamps are written into an immutable verification trail so teams can prove a record existed at a point in time.

Human validation remains explicit

Detection output is explanation-rich, but irreversible customer actions should still be validated by the customer or their designated operator before execution.

Deployment options

Deployment posture is explicit instead of implied.

Dralvia SaaS

Customers can evaluate and operate Dralvia through the hosted public platform surfaces at dralvia.tech, including status visibility and the public docs flow.

Self-hosted / on-prem

The current pricing and onboarding docs support on-prem or self-hosted deployment paths for teams that need local control of storage, secrets, and runtime operations.

Dedicated enterprise variants

Enterprise rollout can include dedicated capacity, regulated deployment constraints, and optional airgapped or custom-operated variants when the commercial agreement requires it.

Next steps

If you need launch, support, or procurement help, use the support and legal contacts above. If you need to report abuse, a vulnerability, or a live incident, use the security contact or `security.txt` path immediately.

If you need deployment detail, pricing posture, or onboarding constraints, continue into the public docs and pricing pages rather than relying on marketing assumptions.