SHT S-01Security
Security starts with where it runs.
VinculixOS is installed on your premises and makes no outbound calls at runtime. Your documents, queries and results never reach us.
SHT S-02Deployment model
No vendor-operated environment.
Because VinculixOS runs entirely inside your infrastructure, the controls that matter most are yours: network, identity, backups. We design the software to work within them.
Two consequences follow, and we would rather state them than leave them implicit:
- Updates are releases you apply. Fixes arrive as versioned releases that you install on your own schedule.
- We have no telemetry. We cannot see your installation, so incident detection on it is a shared responsibility, defined per contract.
SHT S-03Layers of protection
Protection in depth, from your network inward.
Each layer holds on its own. Scroll to take them apart.
01 · AUDIT LOG
Audited
Every search plan and every export is written to the audit log.
02 · SIGNED PROVENANCE
Signed provenance
Each derived fact carries a signed record of its source.
03 · ROLE-BASED ACCESS
Role-based access
What a person may do follows their role; an auditor reads without changing anything.
04 · TENANT ISOLATION
Tenant isolation
Each organisation's data is separated in the database itself, beyond the application's reach.
05 · OFFLINE LICENCE
Offline licence
Verified on site with public-key signatures. Nothing phones home.
06 · YOUR INFRASTRUCTURE
Your infrastructure
Everything above runs inside your network, under your controls.
SHT S-04Controls
Built into the product.
Offline licence verification
Licences are verified with public-key signatures on site. There is no activation server and no phone-home, and the signing key never exists in the codebase or on a build machine.
Signed provenance
Every derived fact carries a digitally signed record of where it came from. A fact without provenance cannot be stored.
Tenant isolation in the database
Each organisation's data is separated by row-level security that the application itself cannot bypass. Cross-tenant access is covered by automated tests.
Modern authentication
Passwords are hashed with a memory-hard function. Sessions use opaque, rotating tokens, and a reused token revokes the session.
Hardened uploads
File types are identified from their content, never from their name. Uploads are bounded in size, page count, decompressed size and processing time.
No outbound network calls
The running system makes no call outside your environment, and models are mounted locally. A check in the build pipeline fails on violation.
Audited queries and exports
Every search records its query plan, and every export its format and counts, in the audit log.
Role-based access
Access is granted by role. An auditor role can read without being able to upload or change anything.
SHT S-05Certifications
What we do not claim.
VinculixOS holds no third-party security certification today. We will not describe a certification, audit or penetration test as complete before it is. When one exists, it will be listed here with its scope and date.
SHT S-06Responsible disclosure
Report a vulnerability.
If you believe you have found a security issue in VinculixOS or in this website, email contact@vinculixos.com with a description, the steps to reproduce it, and its impact. Please do not disclose it publicly until we have had a chance to fix it.
We aim to acknowledge reports within three business days and to share a remediation plan within ten. Our security.txt follows RFC 9116.
SHT S-07This website
This site follows the same rules.
vinculixos.com sets no cookies and loads no third-party scripts or fonts. We use cookieless, aggregate visitor statistics, described in our privacy policy.