Trust & Security

What a security review needs to know about VADIX.

Who does the work, how it is built, which compliance frameworks shape the design, and what happens to data — on this website and inside an engagement. Written for the person filling in the procurement questionnaire.

Last reviewed 6 September 2026 · Questions: hello@vadix.net

1. Who you are working with

Sandeep VadiFounder & Principal Architect · 20+ years in pharma, healthcare, banking and insurance

VADIX is founder-led and senior-only. The person on the discovery call is the person who architects and builds the work; vetted specialists are brought in for larger builds under the same standards and the same accountability.

2. How we build

In your tenant, as code

Platforms are deployed into your Azure subscription with Bicep or Terraform, promoted through DEV, QA and PROD, and handed over with the source, the pipelines and the runbooks. You hold the keys from the first environment.

Private by default

Private Link for PaaS services, managed identities instead of stored secrets, Key Vault for the secrets that must exist, customer-managed keys where the framework asks for them, and least-privilege roles throughout.

Reviewed before it is built

Every significant decision is written down as an Architecture Decision Record and reviewed with you before code is written, so audit evidence is a by-product of the build rather than a project at the end.

Observable in production

Application Insights, Azure Monitor and Defender for Cloud are part of the landing zone, not an afterthought. Alerts, dashboards and cost baselines are delivered with the platform.

3. Compliance frameworks we design for

VADIX designs and builds to these frameworks and has delivered platforms inside organisations that are audited against them. VADIX LLC itself is a small consultancy and is not independently certified against them; where your programme needs an attestation, it sits with the platform you own and the auditors you already use.

FrameworkWhat it means for the build
GxP · 21 CFR Part 11Validated environments, controlled change, audit trails and electronic-signature controls designed into the platform; documentation written to survive an inspection.
HIPAATechnical safeguards for protected health information: encryption in transit and at rest, access logging, minimum-necessary access, and a Business Associate Agreement where one is required.
SOC 2Control mapping for security, availability and confidentiality, with evidence collection automated from Azure Policy, Defender and Monitor.
PCI DSSNetwork segmentation, tokenised payments through a certified processor (for example Stripe), and no cardholder data stored on the platform.
ISO 27001Policy-as-code and continuous compliance monitoring aligned to the control set your ISMS already uses.

4. Data handling in an engagement

5. This website

6. The legal entity

VADIX LLC is a Florida limited liability company operating as VADIX from Tampa Bay. Engagements are governed by a written statement of work; this website is governed by the terms of use. Registered-agent and mailing details are provided on contracts and on request.

Contact for security questionnaires, vendor onboarding and DPAs: hello@vadix.net · (813) 322-5551.

Book a call