Trust · security · transparency

Security you can
understand before the project starts

The Virtek Trust Center brings together our approach to data protection, access, software delivery, operations and incident response. It distinguishes enduring engineering practices from controls designed and contracted for a specific system.

Open trust framework · evolves with our practices

Foundation of trust

Protection begins
before technology selection

We treat security as a property of the whole system: people, architecture, processes and operations. The control set follows the data, threats, criticality and deployment model.

BOUNDARIES

Visible ownership

Before launch, we define Virtek, customer and supplier boundaries, owners, access, change and escalation paths.

ACCESS

Least necessary access

Permissions follow role and task, are reviewed as responsibilities change, and privileged activity receives dedicated control.

EVIDENCE

Decisions leave evidence

Architecture, settings, changes, events, recovery and validation results are documented to the depth agreed for the project.

Engineering practices

Controls only make sense
in the context of a system

This catalogue covers the domains considered across design, implementation and support. The depth of each control is set through assessment and threat modelling.

Control domain

Identity and access

Roles, multi-factor authentication, account lifecycle, service access and privileged control.

Baseline practice
Control domain

Data and placement

Classification, minimisation, encryption, backups, retention, deletion and deployment location.

Designed for the system
Control domain

Secure software delivery

Environment separation, secrets and dependency management, change review, logging and controlled releases.

Baseline practice
Control domain

Infrastructure resilience

Segmentation, redundancy, resource monitoring, recovery and failure-scenario validation.

Designed for the system
Control domain

Events and observability

Agreed logging scope, critical-event monitoring, correlation, retention and access to evidence.

Designed for the system
Control domain

Vulnerabilities and change

Inventory, severity assessment, remediation, exceptions, updates and result verification.

Baseline practice
Control domain

Suppliers and compatibility

Component origin, support lifecycle, updates, compatibility and supply-chain risks are assessed.

Designed for the system
Control domain

Response and recovery

Event classification, containment, communication, restoration, cause analysis and preventive action.

Defined by procedure

Shared responsibility

Security works when
boundaries are explicit

The same service creates different roles in cloud, customer-site and hybrid deployments. This matrix shows the principle; the exact allocation belongs in project and contract documents.

Virtek responsibilityCustomer responsibility

Architecture and threat model

Virtek responsibilityDesign the target environment and recommend controls.

Customer responsibilityProvide process requirements and accept residual risk.

Infrastructure and site

Virtek responsibilityDeliver, configure and operate the agreed scope.

Customer responsibilityProvide physical, organisational and network conditions in the customer domain.

Accounts and authority

Virtek responsibilityConfigure mechanisms, roles and controls in agreed systems.

Customer responsibilityAppoint owners, approve users and report role changes promptly.

Data and retention

Virtek responsibilityImplement agreed protection, backup and deletion mechanisms.

Customer responsibilityDefine data categories, legal basis, retention and permitted processing locations.

Monitoring and incidents

Virtek responsibilityObserve the agreed scope, diagnose and escalate events.

Customer responsibilityProvide contacts, access and decisions requiring system-owner authority.

Change and evolution

Virtek responsibilityDeliver through a controlled process and record outcomes.

Customer responsibilityApprove impact, maintenance windows, priorities and business acceptance criteria.

Deployment control

Architecture follows
the data and the risk

One deployment model does not fit every workload. We select the environment around data, connectivity, performance, control and continuity requirements.

MANAGED CLOUD

Virtek Cloud

Managed service and data deployment on our infrastructure with agreed redundancy, access and support.

ON-PREMISES

Customer site

On-premises infrastructure and AI models remain inside the organisation's controlled perimeter; Virtek designs, deploys and supports the solution.

HYBRID

Hybrid environment

Critical data and components are distributed under explicit exchange, access, backup and recovery rules.

Incident lifecycle

Every incident should
make the system stronger

Response is built around maintaining control: understand impact quickly, contain progression and restore the business process safely.

Detect

Receive a signal from monitoring, a user, an engineer or an external source and preserve the initial evidence.

Assess and contain

Determine impact, severity and boundaries; take action to reduce further damage.

Communicate with purpose

Use the agreed channel to share what is known, what is being done and which decision or access is required.

Restore and verify

Return the function, verify integrity and stability, and observe the system after recovery.

Learn and improve

Record timeline, cause and corrective action; turn material findings into architecture or process changes.

Transparency and documents

The right information
in one place

Public documents explain how the website and company operate. Project architectures, threat models, test protocols and restricted procedures are delivered within the relevant engagement and protected by contract where appropriate.

PRIVACY

Privacy Policy

What personal data the website processes, why, on which basis and how data-subject rights can be exercised.

ACCOUNT

Client Account Agreement

Registration, security, document exchange and use of the client-account functions.

COOKIES

Cookie settings

Control essential site technologies and consent to Yandex Metrica analytics cookies.

DISCLOSURE

IT activity disclosure

Official company information, IT activities, pricing principles and rights to the solutions provided.

Open resource
REGISTER

IT accreditation

Open the official register of accredited Russian IT companies. Use TIN 0274922889 for verification.

Open resource
SUPPORT

Support portal

A single channel for requests, technical questions, security events and a complete interaction history.

Open resource

Report a concern

Found a vulnerability
or suspicious activity?

Do not publish technical details or send passwords and keys in an open message. Create a support request marked “Information Security” or email info@virtek.pro. We will acknowledge it and arrange a secure channel for evidence.

Open a protected request
Important context

This Trust Center describes Virtek's general approach. It is not a certificate, public offer or universal assurance for a specific information system. Architecture, applicable legal requirements, controls, service levels, responsibilities and notification procedures are defined for each project in its contract and project documentation.

Validate before deployment

Discuss requirements
before they become constraints

We will assess critical processes and data, define shared responsibility and propose a security architecture that can be tested.

Discuss security