Trust & security
Posture is a baseline, not a line item.
What a procurement team should be able to read on a single page, without booking a call.
IAM, federation, least-privilege.
No shared admin accounts. Federated identity via customer's IdP where possible. Access review on a documented cadence.
Key Vault / Secrets Manager native.
No secrets in repos, in pipeline variables, or in ticketing systems. Rotated, audited, scoped per environment.
Private-by-default, public-by-decision.
Public endpoints exist where they are correct, not where they are easy. Private link, VNet peering, allowlists by default.
Residency by region, by tenant.
Data residency commitments are honoured at the architecture level: region pinning, replication scopes, backup scopes, all documented.
Audit-ready, not audit-shaped.
Logs, retention, lineage, immutability: designed in, not bolted on. Audit conversations are short.
Customer reference calls.
Arranged on request, after an initial technical conversation. You will hear what we got wrong as well as what we got right.
Certifications · status
Calvrix Ltd is registered in Scotland (company number SC893025) and continues the practice founded as Dove Solutions in 2019. Calvrix Ltd holds no SOC 2 report and no ISO 27001 certificate: it works inside the customer's own compliance scope. If an engagement requires Calvrix to process personal data, we sign a data processing agreement before that work begins. Talk to us about your specific compliance frame: we will tell you whether we already meet it, and where we don't.