Zero-Liability Procurement Kit

What access does Viwago need to review? None.

Most compliance tools reduce your risk by granting a third party admin access to your cloud — and the security review takes months. Viwago inverts that. It is a stateless, zero-custody translation layer: you run the scan, you upload the file, we translate it. There is no access to review — so the review collapses to a single meeting.

What Viwago never asks for

Viwago will never request, and cannot accept:

  • AWS / Azure / GCP IAM roles, access keys, or STS credentials
  • A deployed agent, sidecar, collector, or daemon in your environment
  • Kubernetes service accounts or cluster access
  • Read or write access to your cloud storage (S3, blob, buckets)
  • A persistent connection to your infrastructure or databases
  • Network peering, VPN, or firewall exceptions
  • SSO into your cloud console

If any onboarding step asks for the above, it is not Viwago.

What Viwago actually processes

Full disclosure — the only three things that ever reach us:

Scan output files

JSON you produced with your own scanner and uploaded

Parsed to compute framework mappings; encrypted at rest, tenant-isolated.

Manual attestations

Toggles + evidence links you enter for controls a scanner can’t check

Merged into your posture; tenant-isolated.

A SHA-256 hash

Computed by us from the exact bytes of your uploaded file

Stamped onto your evidence as provenance — the file’s digest, nothing more.

We do not receive your cloud credentials, your infrastructure state, your production data, or any live connection to your systems. The scan ran on your machine; we only see the report it produced.

Architectural boundaries — properties, not promises

Tenant isolation from a verified token

Your data is scoped by a tenantId claim derived only from a verified identity token — never a request parameter a caller can forge. Cross-tenant access is architecturally closed.

Fail-closed by default

An unverified tier resolves to the lowest entitlement; an unparseable upload is rejected; a missing configuration disables a feature rather than opening it. Nothing defaults to ‘allow.’

Encrypted in transit and at rest

Uploaded scan results are encrypted on the wire (TLS) and in storage.

Provenance you can verify without trusting us

Every exported report carries a recomputable SHA-256 seal. Your auditor verifies it in their own browser at /verify — no account, nothing uploaded to us.

Current compliance posture (honest status)

  • SOC 2: in progress — we run Viwago’s own SOC 2 prep on Viwago. Not yet certified; we will not claim a report we don’t hold.
  • Data residency & subprocessors: available on request as part of a DPA.
  • We do not currently claim third-party penetration tests, a bug-bounty program, or a formal uptime SLA. When those exist, they will appear here with dates — not before.

If a claim isn’t listed, assume we haven’t earned it yet.

The one-meeting approval script

Paste this into your internal security channel to fast-track review:

Requesting approval for Viwago (compliance evidence translation).

1. No cloud access required. It never gets an IAM role, agent, or credential — we upload a scan file we already generate ourselves.
2. Blast radius if they're breached: our uploaded scan reports only. No infrastructure access, no live data, no keys. Nothing of ours to pivot from.
3. Data processed: scan JSON we upload, manual attestations we enter, and a SHA-256 hash they compute of our file. That's the complete list.
4. Independently verifiable: every report they produce carries a cryptographic seal we can recompute ourselves at viwago.com/verify, no account needed.

Recommendation: this is a data-processing tool with no access footprint. Standard DPA, no infrastructure review needed.

Nothing to review means nothing to wait for.

Create a free account and translate the scan you already have into sealed, multi-framework evidence.

Create your free account

Or verify our claims first at the public seal-verification tool.