Data sovereignty

Your records live in a database on your own server, in your jurisdiction. No multi-tenant cloud, no vendor copy — a breach of Varda Forms cannot expose your data, because we don't hold it.

Encryption

Automatic HTTPS (TLS 1.2+) in transit. At rest, choose whole-database encryption (SQLCipher) or targeted field-level AES-256-GCM. Keys are kept separate from the app secret and can be rotated.

Authentication & access

Two-factor authentication (TOTP) with backup codes and lockout, an org-wide 2FA policy, SSO, and granular role-based permissions enforced on the server for every request.

Audit & accountability

An immutable audit trail records who did what and when, with before/after snapshots. One-click audit-grade compliance packs (safety & finance) give auditors the evidence they ask for.

Signed, reversible updates

Updates are signature-verified (RS256) and applied only when an administrator approves them — atomically, with automatic rollback on failure. Only the isolated updater can touch the runtime.

Backup & recovery

Built-in backup and restore of the database and keys, so you control retention, residency, and disaster recovery on your own schedule.

Controls & frameworks

Mapped to the standards your auditors know

We publish a controls-mapping document that lines up Varda Forms' security controls against CyberSecure Canada (the CCCS 13 baseline controls), ISO/IEC 27001:2022 Annex A, and the SOC 2 Trust Services Criteria — with a shared-responsibility model that's clear about what the software does versus what you operate.

  • CyberSecure Canada — 13 baseline controls, control by control
  • ISO/IEC 27001:2022 — Annex A themes
  • SOC 2 — Security, Availability, Processing Integrity, Confidentiality, Privacy
  • Shared-responsibility model (vendor vs. customer)

Honest note: this is a vendor self-assessment, not an independent certification. Varda Forms does not yet hold a SOC 2 Type II report or ISO 27001 certificate; CyberSecure Canada is the planned next step. The document states current status plainly.

Security Controls & Compliance Mapping.docx
CyberSecure Canada · 13 controlsMapped
Strong authentication (2FA)Vendor
Encryption at restVendor
Access control (RBAC)Vendor
Backups & recoveryShared
Host patching · perimeterCustomer
Shared responsibility

Clear about who does what

Self-hosting means security is shared. We're upfront about the boundary.

Varda provides

  • Application security
  • Authentication, MFA & RBAC
  • Encryption features
  • Audit logging
  • Signed update packages

You operate

  • Host & OS hardening/patching
  • Network & perimeter
  • Physical security
  • User provisioning
  • Off-site backup storage

Shared

  • Patching (we sign, you apply)
  • Access control (we build, you configure)
  • Backup & recovery (our tools, your schedule)

Responsible disclosure

Found a security issue? We want to hear from you. Email [email protected] — we aim to acknowledge reports promptly and work in good faith toward a fix. Our machine-readable policy lives at /.well-known/security.txt.

Next Step

Bring your security team to the demo

We'll walk through the architecture, the controls mapping, and your deployment requirements together — no sales fluff.