VA Works

Trust & Security

Security and transparency are built into everything we do. We're committed to international standards and actively pursuing formal certifications aligned with our platform.

Global Security Standards We Align With

SOC 1

SOC 1

Not Applicable

A SOC 1 report, under standards set by the American Institute of Certified Public Accountants, audits internal controls only insofar as they impact a customer's financial reporting. SOC 1 applies to service organizations that process or custody client funds or directly impact client financial reporting. VA Works does not perform these activities; therefore, SOC 1 is not applicable to our operating model.

SOC 2

SOC 2

In Progress

A SOC 2 report, under standards set by the American Institute of Certified Public Accountants, evaluates whether a service organization's controls are designed and operating effectively to protect systems and data access. For VA Works, SOC 2 focuses on how we manage workforce access, company-issued devices, endpoint security, and access to client environments. While VA Works does not store or process client customer data, we obtain SOC 2 to provide independent assurance that access to client systems is secured, monitored, and governed appropriately.

SOC 3

SOC 3

Planned

A SOC 3 report is a high-level, public summary of a SOC 2 report issued under standards set by the American Institute of Certified Public Accountants. SOC 3 does not involve additional testing or controls; it is derived directly from an existing SOC 2 report and is designed to provide general assurance without disclosing sensitive system details. VA Works plans to obtain SOC 3 following completion of SOC 2 in order to provide a public trust signal while maintaining appropriate confidentiality.

ISO 27001

ISO 27001

Planned

Information security management systems aligned with international best practices.

GDPR

GDPR

Compliant

The General Data Protection Regulation (GDPR) is a data protection and privacy law enacted by the European Union that governs how personal data of individuals located in the EU is collected, accessed, processed, and protected. GDPR applies based on whose data is involved, not where a company is located.

AES-256 Encryption

AES-256 Encryption

In Use

Advanced Encryption Standard (AES) with a 256-bit key length is a widely recognized encryption standard approved by the National Institute of Standards and Technology (NIST) for protecting sensitive data. AES-256 is used to secure data by rendering it unreadable without authorized cryptographic keys. At VA Works, AES-256 encryption is implemented as part of our broader security controls to protect company-issued devices, authentication credentials, and secure connections used by team members. AES-256 supports our security posture by reducing the risk of unauthorized access or data exposure during device use and system access.

Our Transparency Commitment

We don't claim certifications we haven't earned. This page shows where we are, what we're building toward, and how we evolve with our platform.

Questions about our security approach?

Start Here

0/10 steps explored