VaultAP Docs

Compliance

VaultAP is designed to meet the compliance requirements of organizations that process sensitive financial data. This page outlines our compliance posture and the controls we have in place.

SOC 2 Readiness

VaultAP is designed and built to meet SOC 2 Type I certification criteria. The system architecture and operational controls align with the five Trust Service Criteria:

CriteriaVaultAP Controls
SecurityAES-256 encryption at rest, TLS 1.3 in transit, MFA support, role-based access control, tenant isolation
AvailabilityRedundant infrastructure, automated failover, uptime monitoring
Processing IntegrityHash-chained audit trail, deterministic risk scoring, output validation on AI responses
ConfidentialityPer-tenant encryption keys, data minimization in AI prompts, bank detail hashing
PrivacyConfigurable data retention, right to deletion support, data portability via CSV export

VaultAP is currently in the process of formalizing SOC 2 Type I certification with an independent auditor. Contact us at compliance@vaultap.com for the latest status and to request our security questionnaire.

GDPR Considerations

VaultAP incorporates controls to support compliance with the General Data Protection Regulation (GDPR) for organizations that process data of EU residents.

Data Residency

VaultAP stores data in data centers located in the region you select during onboarding. Available regions include:

  • United States (US East)
  • European Union (EU West)

Data does not leave the selected region for storage or processing. AI model requests are routed to endpoints within the same region where available.

Right to Deletion

VaultAP supports the right to erasure (GDPR Article 17). When a deletion request is received:

Submit deletion request

An Admin submits a data deletion request from Settings > Organization, specifying the scope (e.g., a specific vendor, a user, or all organization data).

Verification

VaultAP verifies the requester's identity and Admin role before proceeding.

Deletion executed

Matching data is permanently deleted from all active systems within 30 days. Backup systems are purged on the next rotation cycle.

Confirmation

The requesting Admin receives a confirmation email documenting what was deleted and when.

Audit trail entries related to deleted data are retained in anonymized form (user identifiers are replaced with a placeholder) to maintain audit trail integrity. This is permitted under GDPR's legitimate interest basis for security logging.

Data Portability

Organizations can export all of their data at any time using the Data Export feature in Settings > Organization. Exports are provided in standard CSV format, covering invoices, vendors, and audit logs.

Data Retention Policies

VaultAP enforces configurable data retention periods. Admins set the retention period in Settings > Organization, choosing from 90 days up to 7 years.

When data exceeds the retention period:

  • Invoice records, vendor data, and associated metadata are permanently deleted.
  • Audit trail entries for deleted records are retained in anonymized form.
  • Deletion occurs automatically via a nightly background job.

Shortening the retention period triggers deletion of data older than the new threshold. This cannot be undone. Ensure your retention period meets your organization's regulatory and business requirements before making changes.

Regular Security Reviews

VaultAP conducts regular security activities to maintain and improve its security posture:

ActivityFrequency
Dependency vulnerability scanningContinuous (automated)
Application security testingQuarterly
Infrastructure penetration testingAnnually (third-party)
Access control reviewQuarterly
Incident response drillSemi-annually
Security policy reviewAnnually

Findings from these reviews are tracked to resolution. Critical and high-severity findings are addressed within 30 days.

Enterprise customers can request a copy of our most recent penetration test summary and security review findings under NDA. Contact compliance@vaultap.com.