Trust
Security
Keeping your websites secure isn't just what VaultLayer does — it's how VaultLayer is built. We protect our platform using industry best practices across infrastructure, encryption, authentication and operational security.
Security Overview
VaultLayer is operated by SquareCode UK Limited. Security is a product requirement, not a brochure page — see also our Trust Centre.
Security Principles
Everything we build follows five principles.
Security is enabled from day one.
Users, integrations and services receive only the permissions they require.
Changes are verified before and after execution.
Every significant action is logged with who, what, when and why.
Automation never means blind automation. Every remediation has evidence, confidence, rollback information and policy controls.
Infrastructure Security
VaultLayer runs on modern cloud infrastructure designed for resilience and security. Our infrastructure includes:
- Encrypted storage
- Private networking
- Automatic operating system security updates
- Continuous monitoring
- Infrastructure health monitoring
- Redundant backups
- Disaster recovery procedures
- Multi-region backup strategy (where supported)
Encryption
We encrypt data both in transit and at rest.
Data in transit
- TLS 1.2+
- HTTPS everywhere
- HSTS enabled
- Modern cipher suites
Data at rest
Sensitive platform data is encrypted using industry-standard encryption provided by our infrastructure providers. Passwords are never stored in plain text.
Authentication
VaultLayer supports secure authentication including:
- Strong password requirements
- Multi-factor authentication (2FA)
- Session management
- Device management
- Audit logging
- Login notifications
- Secure password hashing
AI Security
VaultLayer uses AI to explain operational issues and recommend safe remediations. Our AI principles are simple:
- AI explains—it does not blindly execute.
- Every recommendation includes confidence scoring.
- Every recommendation includes reasoning.
- Every remediation can require approval.
- Every automated action is logged.
Your operational data is not used to train public AI models.
Automation Safety
Every automated change follows the same lifecycle.
No hidden automation. No silent changes. No black box decisions.
Access Controls
Organisations can configure:
- Team roles
- Approval workflows
- Maintenance windows
- Organisation standards
- Execution policies
- Rollback permissions
Audit Trail
Every important action is recorded, including:
- Logins
- Website connections
- Policy changes
- Remediations
- Approvals
- Rollbacks
- Standards changes
- Compliance events
- Integrations
Audit history cannot be modified through the user interface.
Monitoring
We continuously monitor platform health including:
- Infrastructure availability
- Background jobs
- Queue health
- SSL certificates
- Security events
- Performance
- Scheduled maintenance
Live availability: Status page.
Incident Response
If a security incident occurs we follow an established response process.
- Detect — Automated monitoring identifies abnormal behaviour.
- Contain — Affected systems are isolated where necessary.
- Investigate — Our engineers determine impact and root cause.
- Resolve — Services are restored safely.
- Learn — Processes and systems are updated to prevent recurrence.
Where appropriate, affected customers will be notified.
Responsible Disclosure
We welcome reports from security researchers. Please see our Responsible Disclosure Policy.
Compliance Roadmap
We're continuously investing in our security programme.
In progress
- Security policies
- Infrastructure hardening
- Continuous vulnerability management
- Internal security reviews
Certifications
Also planned: Cyber Essentials Plus, SOC 2 Type I and Type II. Certification timelines will be published once formal audits begin — see Compliance.
Questions?
If you have security questions, contact security@vaultlayer.co.uk.