Trust center

What is in place, stated plainly.

Vulnify stores the action: agent, action, resource, destination, and counts. It does not store the contents of the records. This page does not claim a certification, and it does not promise that data stays in a particular country.

Security practices

Tenant isolation

Each organization’s rows are isolated in Postgres with row-level security.

Encrypted vault

Third-party credentials stay in an encrypted vault and are injected only when the decision is ALLOW.

Hash-chained audit

The audit log is append-only and hash-chained per organization. You can verify the chain in the app.

MFA

MFA can be turned on for an account. A high-risk approval asks for a fresh code when it is on. Enforced MFA for a whole organization is not in the product yet.

Signed webhooks

Webhook deliveries are signed with HMAC-SHA256.

CI gates

Changes are checked in CI before a release is published.

The audit trail

Every decision appends one row, hash-chained to the row before it. The chain is per organization, and you can verify it from inside the app.

Subprocessors

These are the parties that process data for the product or for this website. There is no customer-logo wall on this page.

PartyRole
RailwayApplication hosting and Postgres in the United States.
ResendTransactional email, contact-form alerts, and suppression of bounces and complaints.
StripeBilling.
SentryError reporting for the app and the API. It is configured not to send personal data by default and strips credentials; an error message may occasionally include request data. No session replay, and no record contents.
CloudflareCookieless Web Analytics on this website. Object storage (Cloudflare R2) for encrypted database backups. Data: encrypted database backups (all customer data in encrypted form). Location: Cloudflare global infrastructure; no specific region is promised.
GitHubSource code and CI. It does not store the customer database.
Amazon Route 53DNS only. It does not store customer records.

Your data

Export and deletion

From the app settings you can export your data and delete your account. Owners and admins can export the organization (JSON or CSV); only the owner can delete it. Deleting an organization cancels its subscription immediately, with no refund, and cannot be undone. Deleted data can remain in a backup until that copy expires, at most 30 days.

Privacy Policy

Backups

A daily automated backup of the production database runs at 03:00 BRT (Brasília time). It is encrypted with age before it leaves the database host. The decryption key is held only by Vulnify. The file is stored in Cloudflare R2. Cloudflare only holds encrypted files it cannot read. Each copy is kept for at most 30 days, then deleted automatically. Deleted data can remain in a backup until that copy expires, at most 30 days. A restore of a full copy of the production database was tested on 2026-10-02, with row counts verified for every table. Restore drills are scheduled monthly.

Contact messages

A message sent through the contact form is stored for 12 months, and an email alert is sent so we can reply.

Contact form

Privacy contact

The data-protection officer (encarregado, LGPD art. 41) is Giovanni Zadinello, privacy@vulnify.io. That mailbox does not receive mail yet. You can also use the contact form.

Contact form

Responsible disclosure

Report a security issue through the vulnerability disclosure page. Do not post an exploit in public.

Vulnerability disclosure

What crosses the boundary.

Stored

  • Agent, action, resource, destination.
  • How many records, not which rows.
  • The score, the reasons, the policy, the reviewer.
  • A hash-chained audit row per organization.

Not stored

  • The contents of the records.
  • The customer email list itself.
  • Third-party credentials. They stay in the vault.
  • A certification. This site does not award one.

Effective date

Effective October 3, 2026.

  • October 2, 2026. Contact messages are stored for 12 months. Cloudflare is listed for cookieless Web Analytics on this website. Deleting an organization cancels the subscription immediately, with no refund. The privacy contact is named.
  • October 2, 2026. Correction: this page did not claim that off-site backups were running.
  • October 3, 2026. Backups: confirmed daily encrypted backups stored in Cloudflare R2, kept up to 30 days; Cloudflare added as backup storage subprocessor. Restore-test wording made precise. Accuracy fixes from LGPD records review (VLN-48).