Skip to main content

Trust & Security

DVARA is a closed-source AI governance platform — and the free Community Edition is widely distributable. Closed source loses the “anyone can read it” check, so we buy that assurance back with instruments you can verify: independent testing, a live disclosure process, offline operation, and a tamper-evident audit trail.

Responsible disclosure & safe harbor

A live coordinated-disclosure process — report privately via GitHub Private Vulnerability Reporting or security@dvarahq.com, with a published SLA (acknowledged within three business days) and legal safe harbor for good-faith research.

Independent penetration test

DVARA is assessed by an independent third-party penetration test against the boundaries that matter — the gateway, the license and edition trust root, PII and audit integrity, MCP and A2A governance, and multi-tenant isolation. The engagement scope is public; the attestation is available to customers under NDA.

No phone-home · air-gap friendly

The license is a signed envelope validated locally with an offline Ed25519 check — no callback, no revocation list, no required telemetry. DVARA runs fully disconnected, so nothing about your traffic ever leaves your perimeter to reach us.

Tamper-evident, verifiable audit

Every event is HMAC-SHA256 signed and hash-chained on the response path — across LLM, MCP, and agent-to-agent traffic. Chain continuity is verifiable end-to-end (any gap or alteration is detectable), and the log is append-only by application invariant.

Runs in your own perimeter

Self-hosted in your VPC, cloud, or on-prem; multi-tenant with row-level isolation; bring your own provider keys. Data never leaves your infrastructure, and every governance decision happens in-process on the request path.

Source escrow for Enterprise

For continuity assurance, source escrow is available to Enterprise customers on request — so a closed-source dependency is never a single point of failure for a regulated deployment.