Valtik Studios
Trust Center

Our security, compliance, and data practices

We sell security. So our own security has to be right. This page is the documentation enterprise procurement teams ask for. Our practices, roadmap, subprocessors, and policies.

Security Practices

How we secure the engagement

Identity & Access

  • SSO via Google Workspace for internal tools
  • MFA on every account; hardware keys for the highest-risk accounts
  • Principle of least privilege; access scoped to the engagement that needs it
  • Periodic access review aligned to engagement boundaries

Data Protection

  • Full-disk encryption on every workstation (FileVault / LUKS / BitLocker)
  • TLS 1.2+ for all transmission; TLS 1.3 where the endpoint supports it
  • Client engagement data isolated per-client; tokens stored in encrypted vault
  • Retention scoped to engagement + audit requirement; secure deletion at close

Endpoint Security

  • Modern EDR with cloud management plane (Microsoft Defender for Endpoint baseline)
  • Disk encryption mandatory on every workstation
  • Host-based firewall enabled by default
  • Operating system and security patches applied within 30 days of release
  • Documented lost/stolen device procedure with remote wipe

Network Security

  • Cloudflare Zero Trust for production resource access
  • Encrypted DNS on all endpoints
  • Segmented testing environment for active engagement work
  • Per-client folder + token isolation; client data not commingled

Application Security

  • Website hosted on Vercel (SOC 2 Type II, ISO 27001)
  • CSP, HSTS, COOP, COEP headers enforced via middleware
  • Rate limiting on all public forms
  • Cloudflare Turnstile bot mitigation on lead-intake forms
  • Dependabot + SCA scanning in CI; dependencies pinned

Incident Response

  • Documented incident response plan covering engagement-affecting incidents
  • 24-hour notification commitment to clients for incidents touching their data
  • Documented escalation tree to legal counsel and breach-notification counsel
  • Coordination with established IR firms for incidents beyond Valtik's scope
Compliance Roadmap

Current posture and upcoming certifications

We are honest about our certification status. The roadmap below shows what is in place today and what is scheduled. If you need us certified before we can engage, the timeline below is what you need to know.

CT LLC registration and good standing

Connecticut business entity in good standing

Current

SOC 2 Type II

Readiness in progress; Type I targeted for late 2026

In progress

Cyber insurance (E&O + Cyber Liability)

Scoped procurement for 2026; engagement-specific coverage arranged per SOW until policy is in force

In procurement

ISO 27001:2022

Planned for 2027 alongside SOC 2 Type II

Planned

CMMC 2.0 Level 2

For DoD-facing engagements; scoped 2027

Planned
Subprocessors

Vendors with access to engagement data

Vendors we use that may process client data or engagement metadata. All have SOC 2 Type II and/or ISO 27001 certification. Changes to this list are communicated to active clients with 30 days notice.

VendorPurposeCertification
Google WorkspaceEmail, calendar, document storageSOC 2, ISO 27001, ISO 27017/18, FedRAMP
VercelWebsite hostingSOC 2 Type II, ISO 27001
CloudflareDNS, DDoS protection, Zero Trust accessSOC 2, ISO 27001, FedRAMP
GitHubSource code hosting for websiteSOC 2 Type II, ISO 27001
ResendTransactional email deliverySOC 2 Type II
StripePayment processingPCI DSS Level 1, SOC 2, ISO 27001
1PasswordSecrets and password managementSOC 2 Type II, ISO 27001
SignalOut-of-band engagement communicationOpen source, E2EE
Vulnerability Disclosure

Found a security issue in our website?

We maintain a published security.txt at /.well-known/security.txt with current contact information.

Researchers acting in good faith following our policy are protected from legal action. We aim to acknowledge reports within 48 hours, triage within 5 business days, and remediate critical issues within 7 days.

Scope
  • valtikstudios.com and subdomains
  • Valtik-hosted infrastructure (not subprocessor infrastructure)
Out of scope
  • Denial of service attacks
  • Social engineering of employees
  • Physical attacks
  • Subprocessor infrastructure (report directly to the vendor)
Policies

Documents available under NDA

Full policy documents are available to prospects and active clients under NDA. Request via the free-check form with a note on what you need.

Information Security Policy
Access Control Policy
Acceptable Use Policy
Encryption Policy
Incident Response Plan
Business Continuity Plan
Vendor Risk Management Policy
Data Retention and Deletion Policy
Engagement Rules of Engagement (ROE)
Penetration Testing Methodology

Need a vendor security questionnaire completed?

Request the questionnaire response from the free-check form. Include your due date. We typically return completed questionnaires within 2 business days.