Back to VertexNirvana

Security Architecture

Security is part of the architecture.Not an afterthought.

This page documents how VertexNirvana builds, secures, and operates every product we ship — including VN Estate OS — for CTOs, CISOs, procurement teams, and compliance reviewers.

Security architecture

Control layer

Identity · Encryption · Audit · Monitoring

Encryption at rest

AES-256

Encryption in transit

TLS 1.3

Password hashing

bcrypt / Argon2

Vulnerability triage

< 24 hrs

Audit log retention

Policy-driven

Access model

Zero standing privilege

Pen testing

Annual + on-demand

Session expiry

Configurable

Security controls

Six control domains. One security posture.

Security is distributed across identity, data, infrastructure, observability, and compliance rather than isolated to a single control layer.

IAM-01

Identity & Access Management

Role-based access control enforced at every resource layer. Permissions follow least privilege — no standing access, all elevated rights are time-bounded.

  • RBAC at resource level
  • Least-privilege by default
  • Time-bounded elevation
  • SSO / SAML 2.0 ready
ENC-02

Encryption Standards

Data is protected across its lifecycle. AES-256 at rest, TLS 1.3 in transit, key management isolated from application logic.

  • AES-256 at rest
  • TLS 1.3 in transit
  • Isolated key management
  • No plaintext secrets
AUD-03

Audit & Observability

Every action is immutably logged with actor identity, timestamp, and resource context. Audit trails are tamper-evident and exportable.

  • Immutable audit logs
  • Tamper-evident records
  • Configurable retention
  • SIEM-compatible export
INF-04

Infrastructure Security

Systems run in isolated network segments with no unnecessary public endpoints. Dependencies are pinned and scanned continuously.

  • Network segmentation
  • No unnecessary endpoints
  • Dependency scanning
  • 24hr vulnerability triage
MON-05

Continuous Monitoring

Runtime anomaly detection with defined escalation paths and automated alerting, covered by an on-call rotation across time zones.

  • Runtime anomaly detection
  • Automated alerting
  • Defined escalation paths
  • 24/7 on-call coverage
CPL-06

Compliance Readiness

Architecture aligned with major enterprise and regulatory frameworks, backed by control documentation and evidence packages for procurement.

  • Framework-aligned design
  • Control documentation
  • Evidence packages
  • Security questionnaire support

Compliance posture

Framework alignment without the compliance theatre.

Framework alignment status is presented separately from roadmap items so procurement and security reviewers can see the current posture clearly.

Security documentation available

Full control documentation, evidence packs, and completed security questionnaires are available under NDA.

ISO 27001Aligned

Architecture and controls mapped

SOC 2 Type IIAligned

Control framework in place

GDPRAligned

Data residency and processing controls

DPDP Act 2023Aligned

India data protection compliance

HIPAARoadmap

BAA available upon request

PCI DSSRoadmap

Scoping available for card-data flows

Abstract visual representing VertexNirvana's security architecture

VertexNirvana's security architecture — applied consistently across every product we build.

Request documentation

Responsible disclosure

Good-faith security research is welcome.

We welcome good-faith security research. Reports sent to operations@vertexnirvana.com are triaged within 24 hours. We do not pursue legal action against researchers acting in good faith.