VDI and VPN virtual isolation
All work happens inside the virtual desktop, VPN or managed device the client designates. The environment is the client’s, configured to the client’s own standard.
The enterprise client
Engineers in Brazil work inside the client’s own virtual environment, with credentials the client issues and can revoke in seconds. Nothing is exported. Nothing is stored locally. The enterprise keeps complete control of its perimeter, and gains a world-class team inside it.
Client-contained perimeter
The simplest way to secure data across borders is to never move it. The engineer’s laptop is a window into the client’s environment, never a copy of it.
Encrypted and locked down. Display and input only. Holds no client data.
Client-issued credentials per named engineer. Revocable in seconds.
The only route in. Logged and monitored by the client’s own tooling.
Code, data and secrets live here and stay here. Nothing is copied out.
Never on the path: SolerWorks systems, partner systems, personal email, messaging apps, cloud drives or unapproved AI tools.
Network data flow topology
Two views of one structure. In both, SolerWorks governs the process and holds none of the data.
The client’s systems hold the data. Engineers see it through a session the client hosts, with credentials the client controls. SolerWorks is the accountable data processor for that access and never takes custody of a single record.
Swipe sideways to see the full diagram.
The client sets technical priorities through its own ticketing and access systems. The partner leads the team day to day. SolerWorks stays out of the work entirely, which keeps the chain of command short and clear.
Swipe sideways to see the full diagram.
Control baselines
Three layers, each with a clear owner. The full split of responsibilities is set out in how it works.
All work happens inside the virtual desktop, VPN or managed device the client designates. The environment is the client’s, configured to the client’s own standard.
The enterprise client
One credential set per named engineer, under the client’s own multi-factor policy. No shared logins, no shared sessions. SolerWorks requests removal the day a role ends.
Client issues and revokes. SolerWorks tracks.
The client provisions and manages the workspace to its own standard: a corporate device, a virtual desktop or a secure VPN tenancy. Before credentials are issued, each engineer completes security onboarding and attests that the physical endpoint they work from has full-disk encryption, automatic screen lock, a supported and patched operating system, and endpoint protection.
Client provisions and manages. Engineers attest, and SolerWorks keeps the record.
Security controls
The same register is tailored to each client account and shared with its security team.
| Area | Control | Operated by | Evidence |
|---|---|---|---|
| Perimeter | Access only through client-issued credentials and the designated VDI or VPN. | Client | Data processing agreement |
| Perimeter | No client data stored outside the client environment. | SolerWorks | Engineer onboarding records |
| Identity | Multi-factor authentication on every client-issued account. | Client | Client identity provider |
| Personnel | Security onboarding before access. Live register of name, role, systems and access dates. | SolerWorks | Personnel register |
| Personnel | Security and privacy training, completed before access. | SolerWorks | Engineer onboarding records |
| Workspace | Corporate device, virtual desktop or VPN tenancy, provisioned and managed by the client. | Client | Client asset and access records |
| Endpoint | Full-disk encryption, screen lock, supported operating system and endpoint protection on the physical device, attested before credentials are issued. | Engineer and SolerWorks | Signed endpoint attestation |
| Incidents | Engineers report any suspected event to SolerWorks at once. SolerWorks notifies the client without delay, which protects the client’s 72-hour regulatory window. | SolerWorks | Incident notification form |
| Offboarding | Revocation requested the day a role ends. Signed deletion certificate. | SolerWorks and client | Deletion certificate |
Cleared for EU–Brazil data flows
Since January 2026 the European Union and Brazil recognize each other’s data protection as adequate, so remote access from Brazil needs no extra transfer paperwork. Standard contractual clauses are built into every agreement as an automatic fallback.
Offboarding and deprovisioning protocol
When an engineer rolls off, or an engagement ends, SolerWorks runs a seven-step checklist. Every step has an owner, a completion date and an evidence reference.
The protocol closes with a signed deletion certificate, delivered to the client’s security team. Because no data ever left the client environment, the certificate is simple: nothing was retained, by anyone.
SolerWorks requests revocation the day the role ends. The client switches it off.
Any client hardware, security key or token goes back.
The personnel register records the exact revocation date.
Each engineer confirms in writing that they hold no client data.
Any pending privacy request passes to the client.
Final statement between the partner and SolerWorks. Nothing is billed to the client.
Audit records are archived and the deletion certificate is issued.