Trust center

Security

This page is maintained by GuardVault Security Systems to answer common security questions about the GuardVault platform. It describes the controls we operate and the responsibilities shared between GuardVault and our customers.

Platform security controls

GuardVault is designed around the principle that privileged access should be brokered, recorded and least-privilege by default. The following controls are built into the product:

  • Zero standing privileges: credentials are checked out just-in-time with a time-bound TTL.
  • Session brokering and recording: SSH, RDP, database and Kubernetes sessions are proxied, keystroke-logged and hash-chained.
  • Multi-factor authentication: WebAuthn, TOTP and SSO step-up are enforced at the policy layer.
  • Approval workflows: single, dual and quorum approvals before credentials are released.
  • Encryption at rest and in transit: AES-256-GCM for stored secrets, TLS 1.3 for data in transit.
  • Audit logging: immutable, tamper-evident event stream with SIEM export.

Shared responsibility

Security is a shared responsibility. GuardVault provides the control plane, encryption and audit capabilities. Customers are responsible for configuring policies correctly, rotating credentials on schedule, restricting administrator access, keeping identity providers secure, and classifying their own data appropriately.

Self-hosted and cloud deployments

GuardVault can be deployed as a self-hosted control plane or as a managed cloud service. In self-hosted deployments the customer controls the infrastructure, keys and logs. In cloud deployments GuardVault operates the control plane while customer data remains logically isolated by tenant.

Identity and access

Authentication is handled through your existing identity provider (Okta, Microsoft Entra ID, Google Workspace, SAML 2.0 or OIDC). Role-based access control maps IdP groups to GuardVault roles, and every privileged action is logged.

Incident response

We maintain an internal incident response plan and investigate suspected abuse or unauthorized access. Customers are notified of confirmed security incidents that affect their tenant data according to the terms of their subscription.

Reporting vulnerabilities

We welcome responsible disclosure. If you believe you have discovered a security vulnerability in GuardVault, please email security@guardvault.eu with enough detail to reproduce the issue. Do not exploit vulnerabilities beyond what is necessary to confirm them, and do not access data that does not belong to you.

Status and monitoring

Platform status and scheduled maintenance windows are published on our status page. Customers with active subscriptions receive proactive notifications about maintenance and incidents.

Contact

For security questions or to report an issue, contact security@guardvault.eu.

This page is maintained by GuardVault Security Systems and is provided for informational purposes.