Company

Ready for your security review.

The controls your platform, security, and compliance teams ask for — available from day one, not on a roadmap.

  • 99.99%uptime SLA
  • 15 minseverity 1 response
  • 2 yearsaudit log retention
  • US · EU · UKdata residency

SSO and SAML

SAML 2.0 and OIDC with any identity provider, plus SCIM 2.0 for automatic provisioning and deprovisioning.

  • Role-based access down to the project
  • IdP group to project-role mapping
  • Deprovisioning revokes the user's keys

SOC 2 alignment

Controls mapped to SOC 2 Type II, with an annual penetration test and evidence export available under NDA.

  • Current report on request
  • Annual third-party penetration test
  • Completed CAIQ and security package

Private deployments

Run the gateway and router in your VPC, or in a single-tenant region we operate for you.

  • Same API, isolated infrastructure
  • Your own upgrade schedule
  • Egress restricted to allowed providers

Data residency

Pin inference and storage to the US, EU, or UK. Requests that would leave the region fail closed.

  • Regional trace storage
  • Zero-retention mode is one flag
  • Field-level redaction before storage

Dedicated support

A shared channel with the engineers who operate the platform, with contractual response times.

  • Severity 1: 15 minutes, 24/7
  • Named technical contact
  • Quarterly architecture review

Cost governance

Per-team budgets, hard spend caps, and alerts that fire before the invoice does.

  • Caps per project and per key
  • Alerts at 50%, 80%, and 100%
  • Usage export to your finance system
Procurement

What we send on day one.

Security reviews stall on missing documents. Ours are ready before you ask, and our team answers questionnaires directly rather than routing them through sales.

  • SOC 2 Type II report under NDA, with the current audit window.
  • Penetration test summary from the most recent annual test.
  • Architecture and data-flow diagrams covering every region and subprocessor.
  • Completed CAIQ and SIG Lite, refreshed quarterly.
  • DPA with standard contractual clauses, and a current subprocessor list.
  • Business continuity and incident response plans, with tested RTO and RPO figures.

Talk to sales

Tell us about your workload.

A solutions engineer replies within one business day. The first call is technical — bring your architecture, your compliance requirements, and your awkward questions.

  • Architecture review against your current stack
  • Cost modelling from your real traffic mix
  • Security package sent before the first call
  • Proof of concept in your environment, not ours
Thanks — a solutions engineer will reply within one business day.

Or email sales@vantafold.ai