Security

We're a security company. We're held to that.

This page describes how the product is designed to protect customer data and keep scans inside approved scope. We do not list certifications we do not hold.

Data residency

Production workloads run on DigitalOcean App Platform in the DigitalOcean NYC (New York) region. If your procurement requires a different region, raise it during onboarding.

Tenant isolation

Application data paths are organisation-scoped. Authenticated APIs resolve the caller's organisation and query within that boundary. Cross-tenant access is treated as a defect, not a feature.

Encryption

Traffic is served over TLS. Sensitive integration secrets are encrypted at rest using application-managed encryption before storage.

Secrets handling

Secrets are not embedded in client bundles. Runtime secrets live in managed infrastructure configuration. Integration credentials are stored encrypted and decrypted only when needed for a connector call.

Logging and audit trail

Security-relevant actions — including scan approvals — are recorded for accountability. Findings carry evidence suitable for internal review and auditor follow-up.

Scan safety controls

  • Universal approval gate before scans enqueue.
  • Approved-scope enforcement with pause on scope violation.
  • Human confirmation for assistant-driven actions before execution.

Responsible disclosure

If you believe you have found a vulnerability in Vishnora, email [email protected]. Please include steps to reproduce and avoid accessing customer data.