Skip to content

Security evidence for your deployment review.

Review report scope, deployment boundaries and the controls your team will operate. Request sensitive reports under NDA.

Plan your security and procurement review.

Certification does not replace the controls and obligations of your own deployment.

Plan your security and procurement review.
Review materialAvailabilityWhat to check
SOC 2 Type IIReport available under NDAConfirm the reporting period, systems in scope and controls your team must operate.
ISO 27001Certificate available on requestReview the certificate scope and validity for your procurement requirements.
Penetration testingSummary through a controlled requestConfirm the tested components, test date and relevance to your deployment.
Deployment architectureDiscuss with our engineersMap workloads, identity, logs, recordings, updates and support access.
Service commitmentsDefined in your contractReview uptime, response targets, responsibilities and the agreed remedies.
Request review documents

Choose the deployment for your data.

Review workload storage, identity and management connectivity for the deployment you select.

Neverinstall Private Cloud

Your infrastructureIncluding offline sites

Console
Manages
Workloads and storage

Neverinstall Virtual Desktops

Hosted Management Console
Creates, starts and stops desktops

Your deployment

Desktops and workload storage

Disconnected Virtual Desktops

Your site

Local Management Console
Manages
Desktops and workload storage
Neverinstall Private Cloud runs its Console, workloads and storage on your infrastructure, including offline sites. For Neverinstall Virtual Desktops, the hosted Management Console creates, starts and stops desktops in your deployment; disconnected sites run a local Management Console.

Deployment review guides

Review deployment controls.

  • Manage access

    Assign access through your identity provider, roles and policies.

  • Control data transfers

    Configure clipboard, printing and file-transfer policies for desktop sessions.

  • Review activity

    Use session and administrative records to support your review process.

Trust and legal resources.

Security architecture

Identity-checked access, session isolation, data controls, recording, and audit.

Request sensitive reports

SOC reports, penetration-test summaries, questionnaires, and architecture review.

Privacy policy

How Neverinstall handles personal information and data rights.

Cookie policy

How cookies and related technologies are used, plus browser-level controls.

Terms of service

Public service and usage terms for Neverinstall.

Responsible disclosure

Report a vulnerability or coordinate security follow-up directly with the team.

Get product support.

Include the affected product and deployment details.

Live chat

Talk with our support team.

Start live chat
Email support

Send your question and the details we need to help.

Email support

Trust FAQ

Which attestations does Neverinstall hold?

Neverinstall is SOC 2 Type II attested and ISO 27001 certified. The SOC 2 report is available under NDA and sets out its reporting period, systems in scope and customer responsibilities. We share the ISO 27001 certificate on request.

Do you commit to uptime and support response times?

Your contract defines uptime and support response targets, responsibilities and remedies.

Why are some reports request-only?

Sensitive materials such as SOC reports and penetration-test summaries are shared through a controlled review process, often under NDA, rather than published openly.

Where should a security questionnaire go?

Email [email protected] with the questionnaire and your review timeline. Your account team can also coordinate an engineering review.

Where is our data stored?

Where you deploy. Neverinstall Virtual Desktops runs in Neverinstall Cloud, a supported cloud account of yours or your own servers with Neverinstall Private Cloud.

Neverinstall Private Cloud runs on your infrastructure and supports offline operation.

What passes between our deployment and the hosted Console?

The hosted Console manages operations such as creating, starting and stopping desktops. Review its connectivity separately from workload storage. A local Management Console is available for disconnected deployments.

Who owns our data?

You do. Review the applicable DPA for processing covered by your service. It defines Neverinstall’s responsibilities and the handling of personal data on your documented instructions.

What happens when we delete resources?

On Neverinstall Private Cloud, a delete completes only after the platform confirms the infrastructure is gone. A failed delete stays visible and can be retried. Read how our deletion lifecycle works.

Can Neverinstall staff reach our environment?

Support access is agreed with your team. On Neverinstall Private Cloud, our remote support works only from IP addresses you allow, and you can revoke that access at any time.

How do desktop policies control data transfers?

Applications run on the desktop. Administrators configure clipboard, printing and file-transfer policies to control transfers to user devices.

Can audit records go to our SIEM?

Yes. Access and session events from Neverinstall Virtual Desktops, and every administrative action on Private Cloud, can be forwarded to your SIEM.

How do we report a vulnerability?

Email [email protected] with the subject “Responsible security disclosure”. The same contact is listed at /.well-known/security.txt. The team coordinates follow-up with you directly.

Where to go next.