Security is not a feature.
It is the foundation.

Every layer of VAG VDR is built on zero-trust principles, least privilege, and complete auditability.

🔐 Zero-Trust Access

Every request is authenticated and authorised. No implicit trust. Least privilege enforced server-side.

📄 Dynamic Watermarking

Identity, timestamp, IP and custom text applied at view and download time. Traceable and deterrent.

💥 Remote Destruction

Revoke access to documents even after they have been downloaded. Control does not end at the download.

📋 Immutable Audit

Append-only event store. Every significant action is recorded and retained. No silent changes.

⏱️ Time-Bound Access

Automatic expiry on users and permissions. Access ends when it should — without manual cleanup.

🌍 Data Residency

Architecture supports regional deployment. Priority on GCC-friendly options for regulated and regional deals.

🔑 Encryption

AES-256 at rest. TLS 1.3 in transit. Strong isolation between tenants and rooms.

🤖 Permission-Aware AI

AI only ever sees content the requesting user is allowed to access. No training on customer data by default.

AI Data Governance

Intelligence without compromising confidentiality.

  • AI processes only permissioned content
  • Customer data is not used to train shared models
  • All AI answers and summaries include source citations
  • Human approval required for externally visible AI-drafted Q&A
  • Clear model versioning and governance

Compliance Readiness

Designed to support serious security reviews and institutional requirements.

  • GDPR-aligned data handling principles
  • Audit evidence suitable for customer due diligence
  • Path to SOC 2 Type II and ISO 27001
  • Independent penetration testing before launch
  • Secure development lifecycle and secrets management

Control that scales with the deal

From single-bidder processes to multi-party staged disclosure, the permission model is designed for real-world complexity while remaining practical for administrators.

Role-Based + Fine-Grained

Standard roles combined with folder and document-level permissions. Inheritance with the ability to break it where needed.

Bidder Separation

Independent permission groups per external party. Staged disclosure without compromising the integrity of the room.

Auditor Visibility

Dedicated auditor and observer roles with full audit access and controlled content visibility.

Security questions?

We are happy to walk through the architecture, controls, and AI governance model in detail.