/legal/compliance

Compliance Posture

Vulos is built to make compliance a property of the platform, not a questionnaire exercise. This page answers the standard enterprise procurement checklist up-front: data residency, encryption, SOC 2 status, sub-processors, DPA, breach SLA, and retention defaults.

POPIAGDPRUK GDPRCCPALast reviewed 2026-05-23

At a glance

Compliance snapshot

Data Residency

Customer data is stored in the region you choose at org setup. Three regions available: af-south (South Africa), eu-west (EU/EEA), us-east (United States). All data flows — including mail spool, audit logs, and OS state snapshots — stay within the selected region.

Encryption & BYO KMS

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256 via Tigris bucket provider). Enterprise customers may supply their own KMS key via the BYO KMS option — Vulos uses your key to wrap the bucket encryption key; Vulos never holds the plaintext KMS key.

SOC 2 Status

Vulos is SOC 2 Type II in preparation. The audit scope covers Trust Service Criteria: Security, Availability, and Confidentiality. Controls are implemented and operating; formal third-party audit is scheduled for Q4 2026. Security controls are documented at vulos.org/security.

Sub-Processors

Vulos currently uses 5 authorised sub-processors. The full list — including purpose, data categories, and region — is published at /legal/subprocessors. We provide 30-day advance notice of any addition or material change; account holders are notified by email automatically.

Data Processing Agreement

Vulos provides a standard DPA incorporated by reference into the Terms of Service. SMB and Pro customers accept at checkout. Enterprise customers may redline an MSA. The DPA covers POPIA, GDPR, UK GDPR, and CCPA obligations.

Breach Notification SLA

Vulos will notify affected Controllers within 72 hours of becoming aware of a Personal Data breach, as required by GDPR and POPIA. Initial notification includes: known facts, estimated scope, measures taken, and a contact for follow-up. Full incident report follows within 14 days.


Data residency

Supported regions and data flows

When you create a Vulos organisation, you select a bucket region. All customer-owned data — including email attachments, file storage, OS state snapshots, and audit logs — is stored exclusively in that region. Control-plane metadata (account credentials, billing records) is processed in the Fly.io region where the Vulos control plane is deployed (iad, lhr, or fra).

RegionProviderData Flows CoveredApplicable FrameworksStatus
Africa — South AfricaTigris Object Storage
  • Customer bucket data
  • Audit logs
  • Mail queue spool
  • OS state snapshots
POPIA
Available
Europe — EU/EEATigris Object Storage
  • Customer bucket data
  • Audit logs
  • Mail queue spool
  • OS state snapshots
GDPRUK GDPR
Available
United StatesTigris Object Storage
  • Customer bucket data
  • Audit logs
  • Mail queue spool
  • OS state snapshots
CCPA
Available

International transfers of EU/EEA Personal Data rely on Standard Contractual Clauses (Module 2: Controller-to-Processor) incorporated into the DPA. Customers with strict data-sovereignty requirements should select the eu-west or af-south region and use BYO KMS (Enterprise).


Encryption

Encryption posture and BYO KMS

  • In transit — TLS 1.2+

    All traffic between clients and the Vulos control plane, relay, and managed OS instances uses TLS 1.2 or later. TLS 1.0 and 1.1 are disabled. HSTS is enforced on all public endpoints.

  • At rest — AES-256

    Customer bucket data is encrypted at rest using AES-256 via the Tigris Object Storage provider. Per-tenant logical bucket isolation ensures no cross-tenant key reuse.

  • BYO KMS (Enterprise)

    Enterprise orgs may supply their own KMS key (AWS KMS or compatible). Vulos uses the customer key to wrap the bucket encryption key (envelope encryption). Vulos never stores the plaintext KMS key; key rotation is entirely under customer control. Contact security@vulos.org to configure BYO KMS.

  • Password security

    Passwords are hashed with bcrypt (cost factor 12+). New and changed passwords are checked against the HIBP Pwned Passwords database (k-anonymity model; full password never sent).


Retention

Data retention defaults

  • Customer bucket data — owner-controlled

    Data stored in the customer's bucket (email, files, OS snapshots) is retained until the customer deletes it or terminates the service. No automatic expiry; the customer controls retention via bucket lifecycle rules.

  • Audit logs — minimum 12 months

    Append-only audit logs (admin actions, login events, API calls) are retained for a minimum of 12 months in the customer's audit-log bucket. Enterprise customers can extend this to 7 years via bucket lifecycle configuration.

  • Post-termination grace period — 30 days

    Upon service termination, customer data remains accessible in the bucket for 30 days to allow export. After this window, Vulos permanently deletes all copies accessible to it. Bucket credentials remain valid throughout the 30-day window.

  • Billing records — 7 years

    Billing and transaction records are retained for 7 years for tax and financial compliance under South African law (Companies Act, Tax Administration Act).


Incident response

Breach notification SLA

Vulos maintains a documented incident-response procedure. In the event of a confirmed Personal Data breach affecting customer data:

  • T+0 — Detection and containment

    Immediate isolation and containment of affected systems. Incident commander assigned; internal incident log opened.

  • T+72 h — Controller notification (GDPR / POPIA SLA)

    Initial notification to affected Controller(s) within 72 hours of Vulos becoming aware of the breach. Includes: nature of the breach, estimated number of Data Subjects, likely consequences, measures taken, and DPO/security contact.

  • T+14 days — Full incident report

    Detailed post-incident report covering root cause, full scope, remediation steps taken, and preventive measures implemented. Delivered to affected Controllers and, where required, to the relevant supervisory authority.

Security disclosure: security@vulos.org · vulos.org/security


Data Processing Agreement

Read the full standard DPA — covering roles, processing instructions, security measures, sub-processors, data subject rights, retention, and international transfers.

Read the Standard DPA

Sub-Processor List

Full list of 5 authorised sub-processors with purpose, data categories, and region. Updated with 30-day advance notice.

View Sub-Processors

POPIA Posture

Detailed POPIA posture document: lawful processing basis, data-subject rights (s23–s25), Information Officer contact, cross-border transfer posture, and POPIA-specific definitions.

POPIA Posture Document

Enterprise MSA & BYO KMS

Enterprise customers get a redlinable MSA, dedicated SLAs, custom DPA terms, and BYO KMS support. Contact us to start the review.

Contact legal@vulos.org