← Back to VaultDiff

Data Flow

Deployment What happens to your files
Cloud sandbox Files are uploaded over TLS, processed in-memory, PDF returned, files deleted immediately. Retention: zero. No file contents are logged at any point.
Docker enterprise Files never leave the bank's network. The container runs entirely on-premise. No outbound connections are made at runtime.

Data Stored

Encryption

DeploymentIn transitAt rest
Cloud sandbox TLS 1.2+ (Render / Cloudflare) No file data written to disk
Docker enterprise Bank's own TLS policies apply (within internal network) SQLite run log only; bank controls host encryption

Authentication

Vulnerability Management

Audit Trail

Every comparison run produces a SHA-256 stamped, system-generated audit record embedded in the PDF cover page. The record captures: Run ID, engine version, UTC timestamp, file hashes, row/column counts, and tolerance configuration. It cannot be manually altered.

Contact for Security Questions

yuvaraj@vaultdiff.com