Your data is yours to protect
This page describes what actually exists today: how this site is served, how Drift can be verified, and the security standard every client rebuild is built to. No certifications we don't have, no monitoring we don't run.
How we protect your data
Encryption in Transit
virobit.dev is served over modern TLS with HSTS to prevent protocol downgrades. Every system we build and host ships TLS-only with the same policy — no legacy protocol exceptions.
Encryption at Rest
Our build standard for every client system: AES-256 encryption at rest with separately encrypted, rotated backups. Written into the scope, not sold as an add-on.
Role-Based Access
Client rebuilds ship with granular per-user permissions and audit logging by default. Administrative access to anything we host requires MFA and leaves an append-only trail.
Honest Monitoring
This site runs on Cloudflare's global edge. Our status page is updated by hand and says so — when we operate production SaaS, real monitoring comes first.
Verifiable, Not Certified
We hold no compliance certifications yet and won't imply otherwise. What we offer instead: Drift's security model is fully open source, and every rebuild's security posture is documented in your scope — auditable by anyone you hire.
Vulnerability Disclosure
We maintain a responsible disclosure program. If you discover a security vulnerability, email security@virobit.dev and we'll respond within 24 hours.
Hosted by us
or on your own hardware
Every rebuild can run wherever you want it. You own the source either way — hosting is a convenience, never a leash.
☁ Hosted by Virobit
- Zero server procurement or maintenance
- Security updates and patches handled for you
- AES-256 encryption at rest · modern TLS in transit
- MFA enforced on administrative access
- Leave anytime — the deployment comes with you
- Best for teams without dedicated IT staff
🖥 On-Site Self-Hosted
- Complete data sovereignty — nothing leaves your network
- Air-gapped deployment available for high-security environments
- Runs on your VMware, Hyper-V, or bare-metal hardware
- You control retention, access logs, and audit trails
- Designed for government, defense, and enterprise compliance mandates
- Full feature parity with the managed-hosting option
// responsible_disclosure()
If you discover a security vulnerability in Virobit, please email security@virobit.dev with a description of the issue and steps to reproduce it. Do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and remediate. We acknowledge all reports within 24 hours and provide a resolution timeline within 5 business days. We do not take legal action against researchers who act in good faith.
Infrastructure and Hosting
What actually runs today: this website is a static site served from Cloudflare's global edge (with the security headers to match — HSTS, CSP, frame protections). Drift's code is hosted on GitHub in the open. There is no production SaaS platform yet, so we don't describe one.
Client rebuilds are deployed either on infrastructure you own or on managed cloud we run for a flat fee. Either way, the deployment architecture — network isolation, firewalling, backup cadence and retention — is specified in your scope document, where you can hold us to it.
Authentication and Access Control
Every system we build and host follows this standard:
- Bcrypt password hashing with a minimum cost factor of 12
- Optional two-factor authentication (TOTP) for all accounts
- Session tokens with 8-hour expiration and automatic rotation
- IP-based rate limiting on login endpoints
- SSO/SAML integration (Okta, Azure AD, Google Workspace) when included in scope
Honest version of the "employee access" section: Virobit is founder-led and works with a trusted network of engineers for development and audit work. Exactly who can access a system we host for you — by name — is written into your engagement agreement, along with MFA requirements and audit logging. No blanket claims: you always know precisely who can touch your data, because the list is in your contract.
Data Isolation
Client systems aren't multi-tenant rows in a shared database — each rebuild is its own deployment with its own database. Isolation isn't a query filter; it's architecture.
Virobit does not use customer data for any purpose other than delivering the contracted service to that specific customer.
Third-Party Subprocessors
The complete list of third parties this website relies on:
- Cloudflare — site hosting and CDN
- Web3Forms — contact and newsletter form delivery
- GitHub — source code hosting for Drift
- Google Fonts — web font delivery
Subprocessors for a hosted client system are listed in that engagement's scope document, and we notify you before material changes.
Incident Response
In the event of a security incident that affects customer data, we will:
- Begin containment and investigation immediately on detection
- Notify affected customers within 72 hours of confirming a breach
- Provide a written incident report within 14 days, including root cause and remediation steps
- Notify applicable regulators as required by applicable law
No theatrics here: the plan is written down, and in a founder-led shop the person accountable for the incident is the same person who writes you the honest report.
Employee Security
Virobit has no traditional employee org chart — work beyond the founder runs through a trusted network of engineers under contract (see the careers page). These controls apply to anyone touching client work, employee or not:
- Signed confidentiality agreements before any client work
- Principle of least privilege — access limited to what the engagement requires
- Client-system access only when named in that engagement's agreement
- Access revocation within 1 business day of any role change or departure
Contact
For security questions, vulnerability reports, or enterprise security documentation requests, contact our security team at security@virobit.dev.
For general inquiries: hello@virobit.dev · Virobit LLC, Dallas, TX