What access does Viwago need to review? None.
Most compliance tools reduce your risk by granting a third party admin access to your cloud — and the security review takes months. Viwago inverts that. It is a stateless, zero-custody translation layer: you run the scan, you upload the file, we translate it. There is no access to review — so the review collapses to a single meeting.
What Viwago never asks for
Viwago will never request, and cannot accept:
- AWS / Azure / GCP IAM roles, access keys, or STS credentials
- A deployed agent, sidecar, collector, or daemon in your environment
- Kubernetes service accounts or cluster access
- Read or write access to your cloud storage (S3, blob, buckets)
- A persistent connection to your infrastructure or databases
- Network peering, VPN, or firewall exceptions
- SSO into your cloud console
If any onboarding step asks for the above, it is not Viwago.
What Viwago actually processes
Full disclosure — the only three things that ever reach us:
JSON you produced with your own scanner and uploaded
Parsed to compute framework mappings; encrypted at rest, tenant-isolated.
Toggles + evidence links you enter for controls a scanner can’t check
Merged into your posture; tenant-isolated.
Computed by us from the exact bytes of your uploaded file
Stamped onto your evidence as provenance — the file’s digest, nothing more.
We do not receive your cloud credentials, your infrastructure state, your production data, or any live connection to your systems. The scan ran on your machine; we only see the report it produced.
Architectural boundaries — properties, not promises
Your data is scoped by a tenantId claim derived only from a verified identity token — never a request parameter a caller can forge. Cross-tenant access is architecturally closed.
An unverified tier resolves to the lowest entitlement; an unparseable upload is rejected; a missing configuration disables a feature rather than opening it. Nothing defaults to ‘allow.’
Uploaded scan results are encrypted on the wire (TLS) and in storage.
Every exported report carries a recomputable SHA-256 seal. Your auditor verifies it in their own browser at /verify — no account, nothing uploaded to us.
Current compliance posture (honest status)
- SOC 2: in progress — we run Viwago’s own SOC 2 prep on Viwago. Not yet certified; we will not claim a report we don’t hold.
- Data residency & subprocessors: available on request as part of a DPA.
- We do not currently claim third-party penetration tests, a bug-bounty program, or a formal uptime SLA. When those exist, they will appear here with dates — not before.
If a claim isn’t listed, assume we haven’t earned it yet.
The one-meeting approval script
Paste this into your internal security channel to fast-track review:
Requesting approval for Viwago (compliance evidence translation). 1. No cloud access required. It never gets an IAM role, agent, or credential — we upload a scan file we already generate ourselves. 2. Blast radius if they're breached: our uploaded scan reports only. No infrastructure access, no live data, no keys. Nothing of ours to pivot from. 3. Data processed: scan JSON we upload, manual attestations we enter, and a SHA-256 hash they compute of our file. That's the complete list. 4. Independently verifiable: every report they produce carries a cryptographic seal we can recompute ourselves at viwago.com/verify, no account needed. Recommendation: this is a data-processing tool with no access footprint. Standard DPA, no infrastructure review needed.
Nothing to review means nothing to wait for.
Create a free account and translate the scan you already have into sealed, multi-framework evidence.
Create your free accountOr verify our claims first at the public seal-verification tool.