TCVaethra reference

Trust centre

Vaethra's security, availability, privacy and compliance documentation, in one place.

Public documents
16
Under NDA
on request
Security contact
[email protected]
Reviewed
7 September 2026
01About this documentation

The answers a vendor security review asks for, published in advance

A vendor security review usually means a questionnaire, several weeks of email and a call. The questions are largely the same each time, so they are answered here in the detail a reviewer needs: architecture, access control, availability, recovery, incident handling, vulnerability management, how code reaches production, what happens to data over its whole life, and which frameworks we work to.

Two points about scope. Where a control is planned rather than running, the relevant page says so on the page itself rather than only in an appendix. And evidence — recovery test reports, access-control records, security policies, the completed questionnaire — is provided under NDA rather than published, because those documents describe operational detail in a form more useful to an attacker than to a reviewer.

02The documents

Sixteen public pages

Security programme

PageCovers
Security overview Approach, infrastructure, encryption, authentication, monitoring, logging, personnel, physical security, governance, contacts
Architecture Components, trust boundaries, environments, data flows, model processing, tenancy, network boundaries
Access control MFA, least privilege, production access, access reviews, joiners and leavers, credential management, service accounts
Data protection Classification, the licence filter, encryption, retention, deletion, residency, ownership and export
Privacy Categories of personal data, lawful bases, retention, individual rights, privacy governance
Subprocessors The four subprocessors, what each holds, where, their attestations, and 30 days' notice of change

Operations

PageCovers
Availability Uptime measurement, availability architecture, monitoring, maintenance, and the enterprise service level
Business continuity Backups, recovery objectives, five disaster scenarios, recovery procedure and testing
Incident response Classification, detection, process, the 72-hour notification, and the post-incident report
Vulnerability management Dependency monitoring, patch windows, security testing, and responsible disclosure
Secure development The path to production, change management, environment separation, secure coding practice
System status What is running now, answered by the running system
Support Channels, hours, response targets, escalation, notice periods
PageCovers
Compliance Framework status, and a control-by-control map of SOC 2, ISO 27001 Annex A and the GDPR against where each is implemented
Data Processing Agreement Ready to execute, with the Standard Contractual Clauses and the annex of technical and organisational measures
Privacy Policy The formal notice
Terms Terms of use, and how an enterprise agreement differs

Our security contact details are also published at /.well-known/security.txt in the format defined by RFC 9116.

03Documentation provided under NDA

Evidence, available within two business days

The pages above state what our controls are. The documents below evidence that they ran, and are provided to customers and to organisations in an active evaluation under a mutual NDA.

DocumentContents
Completed security questionnaire CAIQ-format, answered in writing. We will also complete yours.
Security policies Access control, change management, incident response, cryptography, acceptable use, vendor management, business continuity
Disaster recovery test report The most recent restore exercise: what was restored, from which backup, how long it took, and what failed
Backup restoration evidence Evidence that backups restore, not that they are taken
Penetration test report Provided once the scheduled independent test is complete
Vulnerability assessment Current dependency and configuration findings with remediation status and dates
Access control evidence Who holds production access, at what level, granted when, reviewed when
Incident response exercise The most recent exercise and what it changed
Risk assessment The register: risk, likelihood, impact, owner, treatment
Vendor assessments Our review of each subprocessor, and their attestations
Compliance evidence Control-by-control mapping with the artefacts behind each

Request it from security@vaethra.com with the entity name and the NDA you would like signed, or ours.

04How these pages are written

Three terms, used consistently

TermMeaning
Live Running in production. Where you can verify it independently, the page says how.
Committed A contractual undertaking — a response time, a notification deadline, a recovery objective. It binds us under the agreement.
Planned Not yet in place, with the dependency stated.

Figures carry the date they were measured. Where a page states a number — tables with row-level security, functions executable by the public role, automated tests — it was taken from the running system on that date and can be re-checked on request.

If you find a statement here that does not match what you can observe, please tell us at security@vaethra.com.

05Downloads

The same documents as files, for the people who file things

A vendor record wants one attachment, not sixteen URLs. Counsel wants a contract that can be printed and signed. And a document read by a language model — now a normal step in a procurement review — is easier to supply as one file than as a crawl. All four carry the date they were issued and are rebuilt from the pages above, so a PDF cannot quietly diverge from what the site says.

Security & Compliance PackageEvery page of this trust centre in one file — architecture, access control, availability, recovery, incidents, vulnerabilities, development, data protection, privacy, subprocessors, compliance and support.PDF · 64 sheets · 1280 KBData Processing AgreementReady to execute. Annex I, the 2021 Standard Contractual Clauses Module Two, the UK Addendum, and the Annex II measures.PDF · 11 sheets · 403 KBPrivacy PolicyPDF · 5 sheets · 246 KBTerms of UsePDF · 4 sheets · 204 KB

Nothing here is under NDA. The evidence pack in §3 — policies, the risk register, recovery test reports, access-control evidence — is a separate request to security@vaethra.com.

06Contacts

Every address, and what it is for

SubjectAddress
Vulnerability reports and security incidents security@vaethra.com
Security questionnaires, evidence requests, DPAs security@vaethra.com
Privacy and data subject requests privacy@vaethra.com
Contracts, terms and licensing legal@vaethra.com
Faults, support and enterprise escalation support@vaethra.com, and +43 678 1261314 for an enterprise Sev-1
API access, pricing, general enquiries contact@vaethra.com
Data providers, about our crawling ops@vaethra.com

Security contact details are also published at /.well-known/security.txt in the format defined by RFC 9116, so a scanner finds them without reading this page.

Registered nameVaethra Technologies LLC
Form and jurisdiction Limited liability company, State of Wyoming, United States
Mailing address 30 N Gould St Ste N, Sheridan, Wyoming 82801, United States
Notices The address above, or legal@vaethra.com

This is the entity that contracts, holds the infrastructure accounts and signs the Data Processing Agreement. It is established in the United States, so for a customer in the EEA or the UK it is the data importer under the Standard Contractual Clauses rather than the exporter.

↑↓ to move · Enter opens the highlighted result