Tenant isolation
Each organization’s rows are isolated in Postgres with row-level security.
Trust center
Vulnify stores the action: agent, action, resource, destination, and counts. It does not store the contents of the records. This page does not claim a certification, and it does not promise that data stays in a particular country.
Each organization’s rows are isolated in Postgres with row-level security.
Third-party credentials stay in an encrypted vault and are injected only when the decision is ALLOW.
The audit log is append-only and hash-chained per organization. You can verify the chain in the app.
MFA can be turned on for an account. A high-risk approval asks for a fresh code when it is on. Enforced MFA for a whole organization is not in the product yet.
Webhook deliveries are signed with HMAC-SHA256.
Changes are checked in CI before a release is published.
Every decision appends one row, hash-chained to the row before it. The chain is per organization, and you can verify it from inside the app.
These are the parties that process data for the product or for this website. There is no customer-logo wall on this page.
| Party | Role |
|---|---|
| Railway | Application hosting and Postgres in the United States. |
| Resend | Transactional email, contact-form alerts, and suppression of bounces and complaints. |
| Stripe | Billing. |
| Sentry | Error reporting for the app and the API. It is configured not to send personal data by default and strips credentials; an error message may occasionally include request data. No session replay, and no record contents. |
| Cloudflare | Cookieless Web Analytics on this website. Object storage (Cloudflare R2) for encrypted database backups. Data: encrypted database backups (all customer data in encrypted form). Location: Cloudflare global infrastructure; no specific region is promised. |
| GitHub | Source code and CI. It does not store the customer database. |
| Amazon Route 53 | DNS only. It does not store customer records. |
From the app settings you can export your data and delete your account. Owners and admins can export the organization (JSON or CSV); only the owner can delete it. Deleting an organization cancels its subscription immediately, with no refund, and cannot be undone. Deleted data can remain in a backup until that copy expires, at most 30 days.
A daily automated backup of the production database runs at 03:00 BRT (Brasília time). It is encrypted with age before it leaves the database host. The decryption key is held only by Vulnify. The file is stored in Cloudflare R2. Cloudflare only holds encrypted files it cannot read. Each copy is kept for at most 30 days, then deleted automatically. Deleted data can remain in a backup until that copy expires, at most 30 days. A restore of a full copy of the production database was tested on 2026-10-02, with row counts verified for every table. Restore drills are scheduled monthly.
A message sent through the contact form is stored for 12 months, and an email alert is sent so we can reply.
The data-protection officer (encarregado, LGPD art. 41) is Giovanni Zadinello, privacy@vulnify.io. That mailbox does not receive mail yet. You can also use the contact form.
Report a security issue through the vulnerability disclosure page. Do not post an exploit in public.
API readiness is the live health check below. It is one response, not an incident history, and there is no published uptime number.
Effective October 3, 2026.