Security and evidence

Evidence, not promises.

A security claim is only worth the evidence behind it and its exact scope. That is why we put both next to every technical claim we make.

How every claim is structured

  1. Claim What we claim – briefly, without exaggeration.
  2. Evidence Which document and which section proves it.
  3. Scope Exactly which product, version and configuration it applies to.

Technical claims and their evidence

Common Criteria

Claim
ViveSec Server has passed an independent Common Criteria evaluation at assurance level EAL2.
Evidence
Common Criteria certificate and Security Target (ISO/IEC 15408:2022, “Assurance level: EAL2”).
Scope
ViveSec Server 1.1.0 in the evaluated configuration. It does not automatically extend to other software versions, to the complete ViVeSec Box hardware and software unit, or to ViVeSec AI Box.
Open document

Security Target

Claim
The security architecture and the evaluation scope are documented and public.
Evidence
ViveSec Server Security Target, version 0.16.1 (2023-02-03, Clarabot Zrt.).
Scope
The document describes the assets to be protected, the threat model and the security functions for the evaluated product version.
Open document

Cryptography

Claim
AES-256-level encryption with documented integrity and signature mechanisms.
Evidence
Security Target, sections 1.4 and 7.11 (AES-SIV, Ed25519, Curve25519); user manual, section 6.1.2 (256-bit security level).
Scope
AES-SIV mode with a 256-bit security level, Ed25519 signatures, Curve25519 key exchange. The manual describes release 1.11.0.
Open document

Own control

Claim
Critical data stays in the organisation's own infrastructure and is processed locally.
Evidence
The ViVeSec Box technical description and the product description in the Security Target (on-premise appliance, local processing).
Scope
ViVeSec Box and ViVeSec AI Box installed on premises. Actual control also depends on the organisation's own operational, network and physical security environment.
Open document

What is not technical evidence – and why we keep it separate

Awards, the CE marking and compliance frameworks matter, but they answer a different question. That is why we do not mix them with security evidence.

Awards and recognition

Professional and market recognition. It shows how the market rates the solution – it does not prove how the security functions work.

Recognition on the homepage

CE marking

The manufacturer's declaration of conformity with EU product requirements. Not a cybersecurity certification.

Downloads

NIS2 · GDPR · ISO/IEC 27001

ViVeSec supports the implementation of several technical security controls. Organisational compliance depends on the entire technical, procedural and governance environment.

NIS2 and compliance details

A question about the scope of a claim?

Our expert walks through the documentation and shows what applies to the environment in question.

Certification claims apply only to the documented, evaluated product version and scope.