Skip to content

Vaultr Journal · Verification

Publishing the boundary test: verify the boundary yourself 

Most vendors ask for trust. We publish the procedure that checks us — edges included.

25 August 2026 · 4 min read

Back to Journal

Security pages usually end at assurance theatre: a badge, a PDF, a promise. The problem with a promise is that you cannot run it. So the security brief ends differently — with a repeatable procedure you can execute on your own machine to check whether local mode really keeps matter processing off the network.

The shape of the test

  • Install the release you were given and note its build identifier — claims are tied to specific builds.
  • Disconnect the machine from every network, or block the Vaultr process at the firewall.
  • Index a sample bundle and run review, drafting and interrogation end to end.
  • Capture traffic for the process for the duration of the run and confirm no matter data appears.
  • Repeat with updates and model downloads enabled, so the deliberate exceptions are visible for what they are.

The edges of the test

A test without stated edges is marketing. This one covers the Vaultr process on one machine and one workload — not every configuration, not your firm's network, and not the configured-endpoint modes where transmission is the point. Run it in the mode you actually intend to use, and treat results from other modes as what they are: a different boundary, documented separately.

We publish this procedure because we expect it to be run. That is the difference between asking for trust and earning it.

No third party has published an independent capture of Vaultr's traffic yet — the trust register says so in those words. If your team runs the test, we would genuinely like to know what you found, including if it is bad. The reporting channels are on the security page, and good-faith reports are answered.