Security you can verify — because the data never leaves your servers.
Varda Forms is self-hosted. There is no shared vendor database and no vendor access to your data. This page documents how the platform protects information and maps its controls to recognized frameworks — so your IT and procurement teams can evaluate it quickly.
Data sovereignty
Your records live in a database on your own server, in your jurisdiction. No multi-tenant cloud, no vendor copy — a breach of Varda Forms cannot expose your data, because we don't hold it.
Encryption
Automatic HTTPS (TLS 1.2+) in transit. At rest, choose whole-database encryption (SQLCipher) or targeted field-level AES-256-GCM. Keys are kept separate from the app secret and can be rotated.
Authentication & access
Two-factor authentication (TOTP) with backup codes and lockout, an org-wide 2FA policy, SSO, and granular role-based permissions enforced on the server for every request.
Audit & accountability
An immutable audit trail records who did what and when, with before/after snapshots. One-click audit-grade compliance packs (safety & finance) give auditors the evidence they ask for.
Signed, reversible updates
Updates are signature-verified (RS256) and applied only when an administrator approves them — atomically, with automatic rollback on failure. Only the isolated updater can touch the runtime.
Backup & recovery
Built-in backup and restore of the database and keys, so you control retention, residency, and disaster recovery on your own schedule.
Mapped to the standards your auditors know
We publish a controls-mapping document that lines up Varda Forms' security controls against CyberSecure Canada (the CCCS 13 baseline controls), ISO/IEC 27001:2022 Annex A, and the SOC 2 Trust Services Criteria — with a shared-responsibility model that's clear about what the software does versus what you operate.
- CyberSecure Canada — 13 baseline controls, control by control
- ISO/IEC 27001:2022 — Annex A themes
- SOC 2 — Security, Availability, Processing Integrity, Confidentiality, Privacy
- Shared-responsibility model (vendor vs. customer)
Honest note: this is a vendor self-assessment, not an independent certification. Varda Forms does not yet hold a SOC 2 Type II report or ISO 27001 certificate; CyberSecure Canada is the planned next step. The document states current status plainly.
Clear about who does what
Self-hosting means security is shared. We're upfront about the boundary.
Varda provides
- Application security
- Authentication, MFA & RBAC
- Encryption features
- Audit logging
- Signed update packages
You operate
- Host & OS hardening/patching
- Network & perimeter
- Physical security
- User provisioning
- Off-site backup storage
Shared
- Patching (we sign, you apply)
- Access control (we build, you configure)
- Backup & recovery (our tools, your schedule)
Responsible disclosure
Found a security issue? We want to hear from you. Email [email protected] — we aim to acknowledge reports promptly and work in good faith toward a fix. Our machine-readable policy lives at /.well-known/security.txt.
Bring your security team to the demo
We'll walk through the architecture, the controls mapping, and your deployment requirements together — no sales fluff.