Trust & Security
Security and transparency are built into everything we do. We're committed to international standards and actively pursuing formal certifications aligned with our platform.
Global Security Standards We Align With

SOC 1
Not ApplicableA SOC 1 report, under standards set by the American Institute of Certified Public Accountants, audits internal controls only insofar as they impact a customer's financial reporting. SOC 1 applies to service organizations that process or custody client funds or directly impact client financial reporting. VA Works does not perform these activities; therefore, SOC 1 is not applicable to our operating model.

SOC 2
In ProgressA SOC 2 report, under standards set by the American Institute of Certified Public Accountants, evaluates whether a service organization's controls are designed and operating effectively to protect systems and data access. For VA Works, SOC 2 focuses on how we manage workforce access, company-issued devices, endpoint security, and access to client environments. While VA Works does not store or process client customer data, we obtain SOC 2 to provide independent assurance that access to client systems is secured, monitored, and governed appropriately.

SOC 3
PlannedA SOC 3 report is a high-level, public summary of a SOC 2 report issued under standards set by the American Institute of Certified Public Accountants. SOC 3 does not involve additional testing or controls; it is derived directly from an existing SOC 2 report and is designed to provide general assurance without disclosing sensitive system details. VA Works plans to obtain SOC 3 following completion of SOC 2 in order to provide a public trust signal while maintaining appropriate confidentiality.

ISO 27001
PlannedInformation security management systems aligned with international best practices.

GDPR
CompliantThe General Data Protection Regulation (GDPR) is a data protection and privacy law enacted by the European Union that governs how personal data of individuals located in the EU is collected, accessed, processed, and protected. GDPR applies based on whose data is involved, not where a company is located.

AES-256 Encryption
In UseAdvanced Encryption Standard (AES) with a 256-bit key length is a widely recognized encryption standard approved by the National Institute of Standards and Technology (NIST) for protecting sensitive data. AES-256 is used to secure data by rendering it unreadable without authorized cryptographic keys. At VA Works, AES-256 encryption is implemented as part of our broader security controls to protect company-issued devices, authentication credentials, and secure connections used by team members. AES-256 supports our security posture by reducing the risk of unauthorized access or data exposure during device use and system access.
Our Transparency Commitment
We don't claim certifications we haven't earned. This page shows where we are, what we're building toward, and how we evolve with our platform.
