Compliance Posture
Vulos is built to make compliance a property of the platform, not a questionnaire exercise. This page answers the standard enterprise procurement checklist up-front: data residency, encryption, SOC 2 status, sub-processors, DPA, breach SLA, and retention defaults.
At a glance
Compliance snapshot
Data Residency
Customer data is stored in the region you choose at org setup. Three regions available: af-south (South Africa), eu-west (EU/EEA), us-east (United States). All data flows — including mail spool, audit logs, and OS state snapshots — stay within the selected region.
Encryption & BYO KMS
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256 via Tigris bucket provider). Enterprise customers may supply their own KMS key via the BYO KMS option — Vulos uses your key to wrap the bucket encryption key; Vulos never holds the plaintext KMS key.
SOC 2 Status
Vulos is SOC 2 Type II in preparation. The audit scope covers Trust Service Criteria: Security, Availability, and Confidentiality. Controls are implemented and operating; formal third-party audit is scheduled for Q4 2026. Security controls are documented at vulos.org/security.
Sub-Processors
Vulos currently uses 5 authorised sub-processors. The full list — including purpose, data categories, and region — is published at /legal/subprocessors. We provide 30-day advance notice of any addition or material change; account holders are notified by email automatically.
Data Processing Agreement
Vulos provides a standard DPA incorporated by reference into the Terms of Service. SMB and Pro customers accept at checkout. Enterprise customers may redline an MSA. The DPA covers POPIA, GDPR, UK GDPR, and CCPA obligations.
Breach Notification SLA
Vulos will notify affected Controllers within 72 hours of becoming aware of a Personal Data breach, as required by GDPR and POPIA. Initial notification includes: known facts, estimated scope, measures taken, and a contact for follow-up. Full incident report follows within 14 days.
Data residency
Supported regions and data flows
When you create a Vulos organisation, you select a bucket region. All customer-owned data — including email attachments, file storage, OS state snapshots, and audit logs — is stored exclusively in that region. Control-plane metadata (account credentials, billing records) is processed in the Fly.io region where the Vulos control plane is deployed (iad, lhr, or fra).
| Region | Provider | Data Flows Covered | Applicable Frameworks | Status |
|---|---|---|---|---|
| Africa — South Africa | Tigris Object Storage |
| POPIA | Available |
| Europe — EU/EEA | Tigris Object Storage |
| GDPRUK GDPR | Available |
| United States | Tigris Object Storage |
| CCPA | Available |
International transfers of EU/EEA Personal Data rely on Standard Contractual Clauses (Module 2: Controller-to-Processor) incorporated into the DPA. Customers with strict data-sovereignty requirements should select the eu-west or af-south region and use BYO KMS (Enterprise).
Encryption
Encryption posture and BYO KMS
In transit — TLS 1.2+
All traffic between clients and the Vulos control plane, relay, and managed OS instances uses TLS 1.2 or later. TLS 1.0 and 1.1 are disabled. HSTS is enforced on all public endpoints.
At rest — AES-256
Customer bucket data is encrypted at rest using AES-256 via the Tigris Object Storage provider. Per-tenant logical bucket isolation ensures no cross-tenant key reuse.
BYO KMS (Enterprise)
Enterprise orgs may supply their own KMS key (AWS KMS or compatible). Vulos uses the customer key to wrap the bucket encryption key (envelope encryption). Vulos never stores the plaintext KMS key; key rotation is entirely under customer control. Contact security@vulos.org to configure BYO KMS.
Password security
Passwords are hashed with bcrypt (cost factor 12+). New and changed passwords are checked against the HIBP Pwned Passwords database (k-anonymity model; full password never sent).
Retention
Data retention defaults
Customer bucket data — owner-controlled
Data stored in the customer's bucket (email, files, OS snapshots) is retained until the customer deletes it or terminates the service. No automatic expiry; the customer controls retention via bucket lifecycle rules.
Audit logs — minimum 12 months
Append-only audit logs (admin actions, login events, API calls) are retained for a minimum of 12 months in the customer's audit-log bucket. Enterprise customers can extend this to 7 years via bucket lifecycle configuration.
Post-termination grace period — 30 days
Upon service termination, customer data remains accessible in the bucket for 30 days to allow export. After this window, Vulos permanently deletes all copies accessible to it. Bucket credentials remain valid throughout the 30-day window.
Billing records — 7 years
Billing and transaction records are retained for 7 years for tax and financial compliance under South African law (Companies Act, Tax Administration Act).
Incident response
Breach notification SLA
Vulos maintains a documented incident-response procedure. In the event of a confirmed Personal Data breach affecting customer data:
T+0 — Detection and containment
Immediate isolation and containment of affected systems. Incident commander assigned; internal incident log opened.
T+72 h — Controller notification (GDPR / POPIA SLA)
Initial notification to affected Controller(s) within 72 hours of Vulos becoming aware of the breach. Includes: nature of the breach, estimated number of Data Subjects, likely consequences, measures taken, and DPO/security contact.
T+14 days — Full incident report
Detailed post-incident report covering root cause, full scope, remediation steps taken, and preventive measures implemented. Delivered to affected Controllers and, where required, to the relevant supervisory authority.
Security disclosure: security@vulos.org · vulos.org/security
Data Processing Agreement
Read the full standard DPA — covering roles, processing instructions, security measures, sub-processors, data subject rights, retention, and international transfers.
Sub-Processor List
Full list of 5 authorised sub-processors with purpose, data categories, and region. Updated with 30-day advance notice.
POPIA Posture
Detailed POPIA posture document: lawful processing basis, data-subject rights (s23–s25), Information Officer contact, cross-border transfer posture, and POPIA-specific definitions.
Enterprise MSA & BYO KMS
Enterprise customers get a redlinable MSA, dedicated SLAs, custom DPA terms, and BYO KMS support. Contact us to start the review.