Security & Compliance

Security built in — and continuously verified.

Darkwyre platforms are engineered to the SOC 2 Trust Services Criteria, run on hardened, self-hosted infrastructure, and are continuously audited and independently security-tested. Security isn't a bolt-on — it's how we build.

SOC 2-aligned controls TLS 1.2 / 1.3 · HSTS Continuously audited Independently tested
deployment · sovereign by design
Sovereign deployment — Darkwyre runs on your own infrastructure, on-premise and air-gap capable, with no cloud dependency
SOC 2Common-Criteria–aligned controls
A+Modern web-security headers & TLS
24/7Automated auditing & monitoring
100%Self-hosted — your data stays yours
SOC 2 alignment

Our controls map to the SOC 2 Common Criteria

Every platform and the infrastructure it runs on are designed against the SOC 2 Trust Services Criteria for Security. A summary of the mapping:

Logical access — CC6.1

Role-based access control with least privilege, hardened authentication, opaque session tokens with immediate revocation, and enforced password policy.

Boundary protection — CC6.6

Host firewall limited to required ports, TLS termination, a strict Content-Security-Policy and full security-header set, and automated brute-force blocking.

Data in transit — CC6.7

TLS 1.2/1.3 only with HSTS and automatic HTTP→HTTPS redirection; certificates auto-renewed.

Integrity & malware — CC6.8

Mandatory access control (AppArmor), package-integrity verification, kernel-module hardening, and application-level CSRF and CSP protection.

Vulnerability management — CC7.1

Continuous automated hardening audits plus external web-vulnerability scanning, with prompt patching and unattended security updates.

Monitoring — CC7.2

Kernel-level audit logging and process accounting, web-server access logs, and a tamper-evident application audit trail.

Incident response — CC7.3/7.4

Automated detection and blocking of malicious traffic, with an investigable audit trail for review and response.

Change management — CC8.1

Every change to the system is re-verified against our security baseline before it's considered done — compliance as code.

Data sovereignty

Self-hosted by design. Platforms run on infrastructure you control and never phone home — your data stays yours.

Independently tested

Verified, not just asserted

Our public infrastructure is regularly scanned with industry security tooling and remediated. The site meets current web-security best practice — TLS with HSTS, a strict Content-Security-Policy, anti-clickjacking, MIME-sniffing protection, and a hardened response-header set — and the host is continuously benchmarked with automated hardening audits.

  • External web-vulnerability scan — high/critical findings remediated.
  • Continuous host-hardening audit — CIS/Lynis-style benchmarking on every change.
  • Automatic security patching and monitored, firewalled infrastructure.
Attestation status

Where we stand — stated plainly

73/100 Latest host-hardening audit — Lynis
1 warnings · benchmarked 2 Aug 2026

Darkwyre operates a SOC 2–aligned control set with continuous internal auditing and independent security testing. A detailed security & controls report is available to customers and partners under NDA.

Formal SOC 2 Type II attestation is performed by an independent auditor over an observation period; contact us for our current status and roadmap.

Evaluating Darkwyre?

Request our security & controls report, or talk to us about your requirements.