Compliance
VaultAP is designed to meet the compliance requirements of organizations that process sensitive financial data. This page outlines our compliance posture and the controls we have in place.
SOC 2 Readiness
VaultAP is designed and built to meet SOC 2 Type I certification criteria. The system architecture and operational controls align with the five Trust Service Criteria:
| Criteria | VaultAP Controls |
|---|---|
| Security | AES-256 encryption at rest, TLS 1.3 in transit, MFA support, role-based access control, tenant isolation |
| Availability | Redundant infrastructure, automated failover, uptime monitoring |
| Processing Integrity | Hash-chained audit trail, deterministic risk scoring, output validation on AI responses |
| Confidentiality | Per-tenant encryption keys, data minimization in AI prompts, bank detail hashing |
| Privacy | Configurable data retention, right to deletion support, data portability via CSV export |
VaultAP is currently in the process of formalizing SOC 2 Type I certification with an independent auditor. Contact us at compliance@vaultap.com for the latest status and to request our security questionnaire.
GDPR Considerations
VaultAP incorporates controls to support compliance with the General Data Protection Regulation (GDPR) for organizations that process data of EU residents.
Data Residency
VaultAP stores data in data centers located in the region you select during onboarding. Available regions include:
- United States (US East)
- European Union (EU West)
Data does not leave the selected region for storage or processing. AI model requests are routed to endpoints within the same region where available.
Right to Deletion
VaultAP supports the right to erasure (GDPR Article 17). When a deletion request is received:
Submit deletion request
An Admin submits a data deletion request from Settings > Organization, specifying the scope (e.g., a specific vendor, a user, or all organization data).
Verification
VaultAP verifies the requester's identity and Admin role before proceeding.
Deletion executed
Matching data is permanently deleted from all active systems within 30 days. Backup systems are purged on the next rotation cycle.
Confirmation
The requesting Admin receives a confirmation email documenting what was deleted and when.
Audit trail entries related to deleted data are retained in anonymized form (user identifiers are replaced with a placeholder) to maintain audit trail integrity. This is permitted under GDPR's legitimate interest basis for security logging.
Data Portability
Organizations can export all of their data at any time using the Data Export feature in Settings > Organization. Exports are provided in standard CSV format, covering invoices, vendors, and audit logs.
Data Retention Policies
VaultAP enforces configurable data retention periods. Admins set the retention period in Settings > Organization, choosing from 90 days up to 7 years.
When data exceeds the retention period:
- Invoice records, vendor data, and associated metadata are permanently deleted.
- Audit trail entries for deleted records are retained in anonymized form.
- Deletion occurs automatically via a nightly background job.
Shortening the retention period triggers deletion of data older than the new threshold. This cannot be undone. Ensure your retention period meets your organization's regulatory and business requirements before making changes.
Regular Security Reviews
VaultAP conducts regular security activities to maintain and improve its security posture:
| Activity | Frequency |
|---|---|
| Dependency vulnerability scanning | Continuous (automated) |
| Application security testing | Quarterly |
| Infrastructure penetration testing | Annually (third-party) |
| Access control review | Quarterly |
| Incident response drill | Semi-annually |
| Security policy review | Annually |
Findings from these reviews are tracked to resolution. Critical and high-severity findings are addressed within 30 days.
Enterprise customers can request a copy of our most recent penetration test summary and security review findings under NDA. Contact compliance@vaultap.com.