Security evidence for your deployment review.
Review report scope, deployment boundaries and the controls your team will operate. Request sensitive reports under NDA.
Plan your security and procurement review.
Certification does not replace the controls and obligations of your own deployment.
| Review material | Availability | What to check |
|---|---|---|
| SOC 2 Type II | Report available under NDA | Confirm the reporting period, systems in scope and controls your team must operate. |
| ISO 27001 | Certificate available on request | Review the certificate scope and validity for your procurement requirements. |
| Penetration testing | Summary through a controlled request | Confirm the tested components, test date and relevance to your deployment. |
| Deployment architecture | Discuss with our engineers | Map workloads, identity, logs, recordings, updates and support access. |
| Service commitments | Defined in your contract | Review uptime, response targets, responsibilities and the agreed remedies. |
Choose the deployment for your data.
Review workload storage, identity and management connectivity for the deployment you select.
Neverinstall Private Cloud
Your infrastructureIncluding offline sites
Neverinstall Virtual Desktops
Your deployment
Disconnected Virtual Desktops
Your site
Deployment review guides
Review deployment controls.
Assign access through your identity provider, roles and policies.
Configure clipboard, printing and file-transfer policies for desktop sessions.
Use session and administrative records to support your review process.
Trust and legal resources.
- Security architecture
Identity-checked access, session isolation, data controls, recording, and audit.
- Request sensitive reports
SOC reports, penetration-test summaries, questionnaires, and architecture review.
- Privacy policy
How Neverinstall handles personal information and data rights.
- Cookie policy
How cookies and related technologies are used, plus browser-level controls.
- Terms of service
Public service and usage terms for Neverinstall.
- Responsible disclosure
Report a vulnerability or coordinate security follow-up directly with the team.
Get product support.
Include the affected product and deployment details.
Trust FAQ
Which attestations does Neverinstall hold?
Neverinstall is SOC 2 Type II attested and ISO 27001 certified. The SOC 2 report is available under NDA and sets out its reporting period, systems in scope and customer responsibilities. We share the ISO 27001 certificate on request.
Do you commit to uptime and support response times?
Your contract defines uptime and support response targets, responsibilities and remedies.
Why are some reports request-only?
Sensitive materials such as SOC reports and penetration-test summaries are shared through a controlled review process, often under NDA, rather than published openly.
Where should a security questionnaire go?
Email [email protected] with the questionnaire and your review timeline. Your account team can also coordinate an engineering review.
Where is our data stored?
Where you deploy. Neverinstall Virtual Desktops runs in Neverinstall Cloud, a supported cloud account of yours or your own servers with Neverinstall Private Cloud.
Neverinstall Private Cloud runs on your infrastructure and supports offline operation.
What passes between our deployment and the hosted Console?
The hosted Console manages operations such as creating, starting and stopping desktops. Review its connectivity separately from workload storage. A local Management Console is available for disconnected deployments.
Who owns our data?
You do. Review the applicable DPA for processing covered by your service. It defines Neverinstall’s responsibilities and the handling of personal data on your documented instructions.
What happens when we delete resources?
On Neverinstall Private Cloud, a delete completes only after the platform confirms the infrastructure is gone. A failed delete stays visible and can be retried. Read how our deletion lifecycle works.
Can Neverinstall staff reach our environment?
Support access is agreed with your team. On Neverinstall Private Cloud, our remote support works only from IP addresses you allow, and you can revoke that access at any time.
How do desktop policies control data transfers?
Applications run on the desktop. Administrators configure clipboard, printing and file-transfer policies to control transfers to user devices.
Can audit records go to our SIEM?
Yes. Access and session events from Neverinstall Virtual Desktops, and every administrative action on Private Cloud, can be forwarded to your SIEM.
How do we report a vulnerability?
Email [email protected] with the subject “Responsible security disclosure”. The same contact is listed at /.well-known/security.txt. The team coordinates follow-up with you directly.