Trust Center
Customers trust us with the most sensitive category of information they hold
Their teams' communications. That is why at vario information security is not a supporting requirement: it is the product. This is how we manage it.
The underlying question
vario is not built to read your communications
It is the objection that opens every evaluation, so we answer it first and with the mechanism in plain sight. Each customer's content is encrypted with a dedicated cryptographic key. vario personnel have no ordinary path to content: exceptional support access is disabled by default, requires written customer authorization, and is immutably logged before it is issued. And only communications from people the customer explicitly added to the defined scope are processed, with prior notice; everything else is discarded before being stored.
Architecture principles
Four principles, each with a mechanism behind it
Minimum access by design
Customer content is encrypted with a dedicated cryptographic key per customer. vario personnel have no ordinary path to content; exceptional support access is disabled by default, requires written customer authorization, and is immutably logged.
Multi-layered customer isolation
Separation between customers is enforced across several layers: application, data platform and cryptography, with continuous automated verification wired to alarms. The scope of each layer is documented and detailed to counterparties under evaluation.
Immutable audit trail
Every relevant operation, including each access to content, is recorded in a log whose immutability is technologically enforced, not merely a matter of policy.
Data minimization
A fail-closed model: only communications from people explicitly added to the scope defined by the customer are processed, with prior notice; everything else is discarded before being stored. Evidence with probative value is preserved in immutable storage with cryptographic integrity verification.
Security program
A management system, not a list of good intentions
vario operates an Information Security Management System formally adopted in August 2026 and structured on ISO/IEC 27001:2022.
Governance
Formally assigned security responsibilities, with a management committee that meets periodically and records its decisions.
Risk management
Documented methodology, formal risk assessment and a Statement of Applicability covering the 93 Annex A controls, maintained as a living document.
Policy framework
Approved policies and procedures covering access control, cryptography, information classification, retention, secure development, suppliers, vulnerability management, remote work, people, monitoring, privacy and incident response, under document control with traceable versioning and approval.
Continuous improvement
An annual review cycle, an annual internal audit under clause 9.2, an independent technical review carried out by a third party, and a certification process underway following a roadmap approved by management.
Certifications and compliance
ISO 27001
ISMS adopted under ISO/IEC 27001:2022, certification underway
GDPR
Compliant by design since launch
LGPD
Compliant by design since launch
Resilience
Recovery capability is not declared: it is tested
Managed automatic backups with point-in-time restore capability, formalized continuity and recovery procedures, and real restoration tests executed and documented on a periodic schedule. Infrastructure is operated as code on a first-tier cloud provider, with verified deployments and automatic rollback.
Compliance
Designed for the legal framework our customers operate in
We operate under Chilean personal data protection law, with Law No. 19.628 in force and an adaptation program for Law No. 21.719 underway. The design is aligned with Chilean labor doctrine on communications monitoring: prior notice to monitored individuals, proportionality and impact assessment built into the product as technical preconditions, not as annexes.
See the legal framework by countryThe 5 questions every company asks us
Can vario read our emails?
No, not without explicit authorization. Content is encrypted with AES-256-GCM using a unique 256-bit key per organization, held in AWS KMS (not on vario's servers). No vario engineer has kms:Decrypt permissions by default. Any support access requires your authorization from the admin dashboard, is logged with timestamp, user and IP in an immutable audit log (SHA-256 signed), and the token expires automatically in 4 hours. You can revoke before expiry by writing to infosec@vario.lat.
What happens if vario gets hacked?
Your data is protected by independent layers. An attacker who compromises the database obtains unreadable ciphertext — the keys live in AWS KMS with completely separate access controls. Reading plaintext would require simultaneously compromising both the database and the KMS system. In the event of a confirmed incident, we notify your security contact within 24 hours of confirmation and assist with regulatory notification (GDPR/LGPD) within 72 hours.
Will our emails be used to train AI?
No. Content is processed within our cloud provider's managed service, which does not share it with the model providers nor use it to train them. It is not an option we switch on: it is how the service works, and it is backed by the data processing agreement with the cloud provider. The first analysis layer, moreover, runs entirely inside our own infrastructure, with no network egress.
Does data leave our geographic region?
We state this precisely, because it is what an evaluator needs to know. Communication content is stored and operated in the platform cloud region, and stays there. The advanced analysis layer runs on a managed service within the same account perimeter, and its routing may process inference outside that region. That international transfer is identified, has a contractual basis with the cloud provider, and includes notice to data subjects. User identity is also delegated to a provider operating in the United States. None of those paths means content is shared with third parties outside the cloud provider.
How do I know vario doesn't mix my data with another company's?
Isolation is applied in overlapping layers. On every authenticated endpoint the customer is derived from the credential, never from the request. Native Row-Level Security policies in forced mode apply to tables with a customer dimension, with a connection role that has no bypass privilege. Isolation is verified automatically at the startup of every process, wired to alarms. And each customer has a dedicated cryptographic key, making cross-customer decryption cryptographically impossible. With one important precision: a limited set of tables is necessarily queried before customer context exists, during authentication and provisioning, and by definition cannot sit under Row-Level Security. There the protection is the application filter, and it is recorded as an exception with periodic review.
Going deeper
Four levels of detail, depending on where you are in the evaluation
We do not publish the internal documents of the management system, because their classification does not allow it. We do share them, at the appropriate level of detail, during the evaluation process.
Level 1
Public summary of our security posture
How
Freely distributable
Level 2
Detailed security posture document
How
Counterparties under evaluation, on request
Level 3
Specific policies and procedures of the management system
How
Under a confidentiality agreement
Level 4
Technical session with evidence, including the Statement of Applicability
How
Vendor assessments and audits
| Level | What | How |
|---|---|---|
| 1 | Public summary of our security posture | Freely distributable |
| 2 | Detailed security posture document | Counterparties under evaluation, on request |
| 3 | Specific policies and procedures of the management system | Under a confidentiality agreement |
| 4 | Technical session with evidence, including the Statement of Applicability | Vendor assessments and audits |
To start any of these levels, write to [email protected]
Start protecting your communications
Tell us about your organization and a member of the vario team will show you how it works.
Talk to the teamNo commitment · The vario team will get back to you soon