Trust Center

Security, transparency, and control.

How DIRVA is built, deployed, and operated — and how to reach us about security.

Security architecture

DIRVA Enterprise runs as an on-premises virtual appliance with role-based access control, encrypted storage and transport, and a complete audit log of platform and agent activity.

Data protection

Customer data remains within the customer-controlled environment. DIRVA does not require security data to be transmitted to external SaaS infrastructure for core operation.

No PII to the LLM

DIRVA never shares personally identifiable information with the AI model. Findings are minimized and redacted inside the platform before any prompt is built — for local and hosted models alike.

Learn more

Deployment security

Hardened appliance images, documented network requirements, and least-privilege integration credentials.

Agent guardrails & identity

Human approval is always in the loop for actions with impact. Every agent has its own identity and runs with least-privilege, scoped credentials and tool allow-lists — enforced inside the platform.

Learn more

Compliance

Certifications and third-party assessments will be published here as they are formally completed. We do not display certifications that have not been achieved.

Security contact

Report a concern to [email protected]. See the disclosure policy below for scope and safe harbor.

Responsible AI

Responsible AI

Human control. A person is always in the loop. Agents propose actions; actions with operational impact require human approval before execution. Any pre-approved automation is limited to a narrow, human-defined scope that can be revoked at any time.

Agent identity and access control. Each agent has a distinct identity, so its actions are attributable and revocable. Agents operate with least-privilege, scoped credentials and tool allow-lists enforced by the DIRVA policy engine inside the customer environment. These controls are internal to the platform and not dependent on external services.

Transparency and auditability. Agent reasoning, tool calls, inputs, and outputs are logged and attached to the finding record so every action can be reviewed.

Data and model control. DIRVA supports a controlled model architecture, including local or private model options where configured. Customer data remains within the customer-controlled environment.

No PII to the model. DIRVA never shares personally identifiable information with the LLM. Prompts are constructed from minimized, redacted findings — personal identifiers, credentials, and customer records are removed by the platform before any model is called, regardless of whether the model runs locally or is hosted.

Scope and limits. DIRVA assists security teams; it does not replace their judgment. Recommendations should be reviewed by qualified personnel before actions with significant impact are approved.

Security research

Vulnerability Disclosure Policy

We welcome good-faith security research on DIRVA products and infrastructure.

How to report. Email [email protected] with a description of the issue, affected component, steps to reproduce, and any supporting material. We acknowledge reports within 3 business days.

Scope. DIRVA products and DIRVA-operated infrastructure. Customer deployments are governed by the customer's own policies; do not test customer environments without their authorization.

Guidelines. Do not access, modify, or exfiltrate data that is not your own; do not degrade service; give us reasonable time to remediate before public disclosure.

Safe harbor. We will not pursue legal action against researchers who act in good faith and in accordance with this policy.

Get started

Questions about security or deployment?

Our team can walk through architecture, data handling, and model options for your environment.