Trust

Security

Keeping your websites secure isn't just what VaultLayer does — it's how VaultLayer is built. We protect our platform using industry best practices across infrastructure, encryption, authentication and operational security.

Security Overview

VaultLayer is operated by SquareCode UK Limited. Security is a product requirement, not a brochure page — see also our Trust Centre.

Security Principles

Everything we build follows five principles.

Protect by default

Security is enabled from day one.

Least privilege

Users, integrations and services receive only the permissions they require.

Verify everything

Changes are verified before and after execution.

Full auditability

Every significant action is logged with who, what, when and why.

Secure automation

Automation never means blind automation. Every remediation has evidence, confidence, rollback information and policy controls.

Infrastructure Security

VaultLayer runs on modern cloud infrastructure designed for resilience and security. Our infrastructure includes:

  • Encrypted storage
  • Private networking
  • Automatic operating system security updates
  • Continuous monitoring
  • Infrastructure health monitoring
  • Redundant backups
  • Disaster recovery procedures
  • Multi-region backup strategy (where supported)

Encryption

We encrypt data both in transit and at rest.

Data in transit

  • TLS 1.2+
  • HTTPS everywhere
  • HSTS enabled
  • Modern cipher suites

Data at rest

Sensitive platform data is encrypted using industry-standard encryption provided by our infrastructure providers. Passwords are never stored in plain text.

Authentication

VaultLayer supports secure authentication including:

  • Strong password requirements
  • Multi-factor authentication (2FA)
  • Session management
  • Device management
  • Audit logging
  • Login notifications
  • Secure password hashing

AI Security

VaultLayer uses AI to explain operational issues and recommend safe remediations. Our AI principles are simple:

  • AI explains—it does not blindly execute.
  • Every recommendation includes confidence scoring.
  • Every recommendation includes reasoning.
  • Every remediation can require approval.
  • Every automated action is logged.

Your operational data is not used to train public AI models.

Automation Safety

Every automated change follows the same lifecycle.

Detect
Explain
Preview
Approve (if required)
Execute
Verify
Evidence
Rollback (where supported)

No hidden automation. No silent changes. No black box decisions.

Access Controls

Organisations can configure:

  • Team roles
  • Approval workflows
  • Maintenance windows
  • Organisation standards
  • Execution policies
  • Rollback permissions

Audit Trail

Every important action is recorded, including:

  • Logins
  • Website connections
  • Policy changes
  • Remediations
  • Approvals
  • Rollbacks
  • Standards changes
  • Compliance events
  • Integrations

Audit history cannot be modified through the user interface.

Monitoring

We continuously monitor platform health including:

  • Infrastructure availability
  • Background jobs
  • Queue health
  • SSL certificates
  • Security events
  • Performance
  • Scheduled maintenance

Live availability: Status page.

Incident Response

If a security incident occurs we follow an established response process.

  1. Detect — Automated monitoring identifies abnormal behaviour.
  2. Contain — Affected systems are isolated where necessary.
  3. Investigate — Our engineers determine impact and root cause.
  4. Resolve — Services are restored safely.
  5. Learn — Processes and systems are updated to prevent recurrence.

Where appropriate, affected customers will be notified.

Responsible Disclosure

We welcome reports from security researchers. Please see our Responsible Disclosure Policy.

Report a vulnerability →

Compliance Roadmap

We're continuously investing in our security programme.

In progress

  • Security policies
  • Infrastructure hardening
  • Continuous vulnerability management
  • Internal security reviews

Certifications

SOC 2
Coming soon
Cyber Essentials
Coming soon
ISO 27001
Planned

Also planned: Cyber Essentials Plus, SOC 2 Type I and Type II. Certification timelines will be published once formal audits begin — see Compliance.

Questions?

If you have security questions, contact security@vaultlayer.co.uk.