One public trust surface for contact paths, legal posture, evidence model, and deployment reality.
This page is the public checkpoint for how Dralvia handles security reporting, company/legal visibility, evidence backed outputs, and deployment expectations during the current launch readiness phase.
It is intentionally static and repo backed so the trust surface stays available even when the product runtime is under maintenance or a live API surface is degraded.
What this page covers
Support
Use the support mailbox for blocking product issues, onboarding questions, and operational follow up.
[email protected]Security disclosures
Report vulnerabilities, active abuse, or suspicious security behavior through the security contact.
[email protected]Legal and privacy
Route privacy, DPA, subprocessor, and legal-notice questions through the legal contact.
[email protected]Vendor security review
The answers to your security questionnaire, on one page.
If your team sends a vendor security questionnaire, these are the common answers up front, with a link to the detail for each. Send this page to your security reviewer to skip the back and forth.
Where is data hosted, and how long is it kept?
Primary hosting is in the EEA. Each scanner keeps only what it needs, with per-scanner retention spelled out, and customers can run self-hosted for full local control of storage.
Data handling and retentionHow do you safely scan malicious URLs and files?
Live malicious content is opened only inside network-isolated sandboxes that have no route to our internal systems or datastores. Their only outbound path is a filtered gateway that blocks private and internal network addresses, and each runs under strict CPU, memory, and process limits.
How Dralvia is builtHow is customer data isolated and protected?
Per-workspace isolation with scoped API keys and role-based access. Traffic is served over TLS, and scan inputs/outputs are tied to the workspace that created them.
Architecture and isolationWho are your subprocessors?
The current infrastructure and delivery subprocessors are published and kept up to date as a crawlable list.
Subprocessor inventoryHow do we report a vulnerability or incident?
A published responsible-disclosure path plus a machine-readable security.txt, monitored by the security contact.
Responsible disclosureHow do you handle data processing agreements?
A DPA overview describes the processor posture, transfer model, and contract expectations for buyers who need a signed agreement.
DPA overviewWhat is your compliance posture today?
We do not claim certifications we do not hold. Instead, this trust surface gives you the underlying evidence: architecture, data handling, subprocessors, disclosure, and signed EvidencePack records for audit.
What ships todayLegal posture
Public legal materials stay linked from one place.
Dralvia publishes the company notice, privacy disclosures, terms, cookie/storage policy, DPA overview, and subprocessor list as crawlable marketing routes instead of burying them behind product-only hash navigation.
Legal Notice
Company identity, registry details, and public legal contact path.
Privacy Policy
Controller identity, data categories, legal bases, and retention posture.
Terms of Service
Commercial scope, customer responsibilities, and service disclaimers.
Cookies & Storage
Public cookie behavior for the marketing and documentation surfaces.
DPA Overview
Processor posture, transfer model, and contract expectations.
Subprocessors
Current public infrastructure and delivery subprocessors.
Evidence model
Trust in Dralvia comes from recorded evidence, not only verdict labels.
EvidencePack exports
Dralvia records signed EvidencePack artifacts so customers can keep the scan inputs, outputs, and reasoning chain together for incident handling and audit work.
Transparency log verification
Where transparency logging is enabled, EvidencePack hashes and timestamps are written into an immutable verification trail so teams can prove a record existed at a point in time.
Human validation remains explicit
Detection output is explanation-rich, but irreversible customer actions should still be validated by the customer or their designated operator before execution.
Deployment options
Deployment posture is explicit instead of implied.
Dralvia SaaS
Customers can evaluate and operate Dralvia through the hosted public platform surfaces at dralvia.tech, including status visibility and the public docs flow.
Self-hosted / on-prem
The current pricing and onboarding docs support on-prem or self-hosted deployment paths for teams that need local control of storage, secrets, and runtime operations.
Dedicated enterprise variants
Enterprise rollout can include dedicated capacity, regulated deployment constraints, and optional airgapped or custom-operated variants when the commercial agreement requires it.
Operational trust links
Status, disclosure, and docs remain one click away.
Public status
Live, down, and maintenance state for the public platform, docs, marketing, and API surfaces.
security.txt
Machine-readable security disclosure path for the marketing domain, with canonical links back to the primary product policy.
Trust docs
External documentation describing this trust page and the public trust surface.
Next steps
If you need launch, support, or procurement help, use the support and legal contacts above. If you need to report abuse, a vulnerability, or a live incident, use the security contact or `security.txt` path immediately.
If you need deployment detail, pricing posture, or onboarding constraints, continue into the public docs and pricing pages rather than relying on marketing assumptions.