Trust & Security
DVARA is a closed-source AI governance platform — and the free Community Edition is widely distributable. Closed source loses the “anyone can read it” check, so we buy that assurance back with instruments you can verify: independent testing, a live disclosure process, offline operation, and a tamper-evident audit trail.
Responsible disclosure & safe harbor
A live coordinated-disclosure process — report privately via GitHub Private Vulnerability Reporting or security@dvarahq.com, with a published SLA (acknowledged within three business days) and legal safe harbor for good-faith research.
Independent penetration test
DVARA is assessed by an independent third-party penetration test against the boundaries that matter — the gateway, the license and edition trust root, PII and audit integrity, MCP and A2A governance, and multi-tenant isolation. The engagement scope is public; the attestation is available to customers under NDA.
No phone-home · air-gap friendly
The license is a signed envelope validated locally with an offline Ed25519 check — no callback, no revocation list, no required telemetry. DVARA runs fully disconnected, so nothing about your traffic ever leaves your perimeter to reach us.
Tamper-evident, verifiable audit
Every event is HMAC-SHA256 signed and hash-chained on the response path — across LLM, MCP, and agent-to-agent traffic. Chain continuity is verifiable end-to-end (any gap or alteration is detectable), and the log is append-only by application invariant.
Runs in your own perimeter
Self-hosted in your VPC, cloud, or on-prem; multi-tenant with row-level isolation; bring your own provider keys. Data never leaves your infrastructure, and every governance decision happens in-process on the request path.
Source escrow for Enterprise
For continuity assurance, source escrow is available to Enterprise customers on request — so a closed-source dependency is never a single point of failure for a regulated deployment.