Trust center
Everything a security review needs, in one place. dvt pushes queries down to your warehouse and returns only the rows needed to render a chart, so your data rows and values never have to live in our infrastructure. Here's how we back that up.
Data handling at a glance
dvt never hosts your data rows or values
Queries run in your warehouse, on your compute. Only result rows return, in memory, and they're discarded after rendering: never persisted to our database.
Credentials stay encrypted
Warehouse credentials are envelope-encrypted; our database holds only ciphertext, and the key that unwraps them never leaves the engine tier.
Least-privilege access
Capability-based roles gate every action, every record is scoped to an organization, and sensitive actions land in an append-only audit log.
Data is retained briefly
Personal data from departed accounts is scrubbed within 90 days, and image exports are deleted within 30. We keep only what we need.
Catalog structure is opt-in
An org admin can opt a connection into catalog sync, off by default per connection. It stores names/types/comments only, never data rows or values, and turning it back off deletes the synced structure immediately. See the security overview for the full boundary.
Questionnaire-ready artifacts
The documents and policies a vendor-security review asks for. If you need something that isn't here (a DPA, a completed questionnaire, or advance notice of subprocessor changes), email [email protected].
Security overview
How data flows, what we store, encryption, access controls, and our continuous testing program.
Read the overview →Subprocessors
Every third-party service that supports dvt, what each one processes, and where.
View subprocessors →Vulnerability disclosure
Our machine-readable security policy and good-faith research commitment.
security.txt →Security contact
Report an issue, request a DPA, or run a security review with our team.
[email protected] →Compliance roadmap
We hold continuous, evidence-backed readiness and pursue formal certification when a deal calls for it: readiness now, audit on demand.
- SOC 2: readiness now, audit on trigger. dvt is not yet SOC 2 audited. Our controls map to the SOC 2 Common Criteria, and our CI produces a continuous, timestamped evidence trail. We'll commission a formal Type II audit when an enterprise engagement calls for it.
- Continuous security testing. Static analysis, dependency and secret scanning, and a layered dynamic-testing pyramid run on every change; see the security overview for the full program.
- Penetration testing. We don't have a third-party pentest under contract yet; automated testing doesn't replace one, and we'll commission it when an enterprise engagement calls for it.
Need a DPA, a security questionnaire completed, or a call with our team? Email [email protected].