Trust
Security and trust
What every system we deliver ships with, stated the way a security reviewer needs it.
DCI Brands LLC, trading as Vavus Business Solutions, 312 W 2nd Street, Casper, WY 82601, United States. Effective 3 September 2026.
1. The short version
Client-side encryption by default. End-to-end encrypted messaging. BAA-backed healthcare delivery. Six-year audit retention. Managed cloud, on-premise, and air-gapped deployment paths. Zero protected health information in application logs by design. Every system in the catalog is delivered on the same security foundation that Vavus AI runs on, and this page describes that foundation. We publish what we can show; if your review needs something that is not listed here, ask and we answer within a business day.
2. Encryption
Stored history, documents, and audio are encrypted on the user's device before storage, with a per-user account master key held in the device keychain wrapping per-artifact keys. Messaging uses end-to-end encryption on the Signal Protocol, so the operator of the system cannot read message content. Transport is TLS 1.2 or higher at the load balancer; legacy server-side data at rest is AES-256-GCM, read-only.
We do not pretend every step is a magic box. Live speech has to be processed briefly in memory to be recognized, translated, and spoken before storage rules apply, and a feature that a server must compute, such as tallying a group poll, cannot be end-to-end encrypted; in healthcare deployments such features are disabled. Where a user explicitly consents to a server-side operation on one item, that consent is recorded and audited.
3. Access and account security
- Owner, admin, member, and viewer roles with team-level control.
- SAML 2.0 single sign-on with the major identity providers for enterprise accounts.
- Brute-force protection with exponential backoff and account lockout.
- Token revocation on logout and on password change; separate stream tokens for live sessions.
- Breach detection on unusual activity, location changes, and IP anomalies.
- A web application firewall with rate limiting and injection blocking in front of every managed deployment.
- Secure deletion, overwrite before unlink, for any asset that may contain protected health information.
4. Audit logging
Audit logs record metadata-only events: who did what, when, and from which device. They never contain protected health information, message content, or translation content. They are retained for six years, and for enterprise deployments they can be exported as JSON or streamed to a customer-controlled SIEM.
5. Healthcare
Healthcare engagements onboard under a signed Business Associate Agreement, and each workflow is reviewed with you, clinical fit and operational guardrails, before a single PHI event flows through the system. The delivered posture is HIPAA-aligned: 8-hour session token expiry, 15-minute idle timeout, secure deletion of PHI assets, zero PHI in application logs, and six-year audit retention.
Nothing we deliver is a medical device. Output that touches patient care must be reviewed by a qualified clinician, and no system of ours replaces a professional medical interpreter where federal or state law requires one.
6. Privacy and data rights
Authenticated data export and an account-deletion path are part of every delivered system. We never sell user data and never use customer content to train models. Consent state is tracked per user, cookie consent on the web is granular, and the sub-processors behind a managed deployment are configured to keep content out of model training and never receive a user's account identity. A named sub-processor list is provided under the data processing agreement.
7. Where it runs
The managed cloud runs across a primary United States region with European and Asian edges behind a global load balancer. Regional data residency is scoped in the quote. Most catalog entries can also be delivered on your own cloud or on-premise — each entry lists its delivery modes — and entries with no external provider dependency can run fully air-gapped, with the entire stack, AI included, inside your perimeter and nothing leaving your network.
8. Support that stays in-house
Support conversations run on infrastructure we host ourselves, so support transcripts are never handed to a third-party vendor. That matters when a support thread contains a screenshot of patient data.
9. Documentation for your review
On request we provide the security documentation pack: encryption architecture diagrams, key management, the audit log schema, deployment topologies, the Business Associate Agreement template, and the data processing agreement template. Request the pack. For security coordination, write to constantine@vavusai.com.