Trust center
Everything a security review needs, in one place. dvt pushes queries down to your warehouse and returns only the rows needed to render a chart, so your data rows and values never have to live in our infrastructure. Here's how we back that up.
Data handling at a glance
dvt never hosts your data rows or values
Queries run in your warehouse, on your compute. Only result rows return, in memory, and they're discarded after rendering: never persisted to our database.
Credentials stay encrypted
Warehouse credentials are envelope-encrypted; our database holds only ciphertext, and the key that unwraps them never leaves the engine tier.
Least-privilege access
Capability-based roles gate every action, every record is scoped to an organization, and sensitive actions land in an append-only audit log.
Retention, stated plainly
When a user's account is deleted or an organization closes, their account details — email, name, avatar — are de-identified after 90 days. Image exports have no deletion schedule — they're retained until you ask us to delete them, and we'd rather say that than imply a timetable we don't run. A couple of records outlive that scrub, such as a scheduled-export recipient address or a note in a change history; the privacy policy has the detail, and we remove them on request.
Catalog structure is opt-in
An org admin can opt a connection into catalog sync, off by default per connection. It stores names/types/comments only, never data rows or values, and turning it back off deletes the synced structure immediately. See the security overview for the full boundary.
Questionnaire-ready artifacts
The documents and policies a vendor-security review asks for. If you need something that isn't here (a DPA, a completed questionnaire, or advance notice of subprocessor changes), email security@dvt.dev.
Security overview
How data flows, what we store, encryption, access controls, and our continuous testing program.
Read the overview →Subprocessors
Every third-party service that supports dvt, what each one processes, and where.
View subprocessors →Vulnerability disclosure
Our machine-readable security policy and good-faith research commitment.
security.txt →Security contact
Report an issue, request a DPA, or run a security review with our team.
security@dvt.dev →Compliance roadmap
We hold continuous, evidence-backed readiness and pursue formal certification when a deal calls for it: readiness now, audit on demand.
- SOC 2: readiness now, audit on trigger. dvt is not yet SOC 2 audited. Our controls map to the SOC 2 Common Criteria, and our CI produces a continuous, timestamped evidence trail. We'll commission a formal Type II audit when an enterprise engagement calls for it.
- Continuous security testing. Static analysis, dependency and secret scanning, and a layered dynamic-testing pyramid run on every change; see the security overview for the full program.
- Penetration testing. We don't have a third-party pentest under contract yet; automated testing doesn't replace one, and we'll commission it when an enterprise engagement calls for it.
Need a DPA, a security questionnaire completed, or a call with our team? Emailsecurity@dvt.dev.