Security
Security
VSDR handles the accounts you connect and the prospects you target. This page describes the controls we operate and how to report a problem.
Last updated:
Data protection
- All traffic between your browser and our systems is encrypted in transit using TLS.
- Customer and prospect data is encrypted at rest by our infrastructure providers.
- Connected-account credentials and API tokens are stored encrypted and are never exposed in the interface or in logs.
Access control
- Workspace access is scoped per customer; one workspace cannot read another's data.
- Internal access to production follows least privilege and is granted only to staff who need it for support or operations.
- Team member permissions are managed by the workspace owner.
Infrastructure
We run on established cloud providers with their own physical and network security programmes. Backups are taken regularly and restoration is tested. Application dependencies are monitored and patched.
Sub-processors
We use a limited set of sub-processors for hosting, email delivery, payments and analytics. Each is contractually bound to protect data. A current list is available on request.
Incident response
We monitor for anomalous activity and investigate alerts. If an incident affects your data, we will notify affected customers without undue delay and describe what happened, what we did, and what you should do.
Reporting a vulnerability
If you believe you have found a security issue, email [email protected] with the subject “Security”. Please give us a reasonable window to investigate and fix before public disclosure. We do not pursue legal action against researchers who report in good faith and avoid privacy violations, service degradation and data destruction.
Compliance questions
For security reviews, data processing agreements or questionnaires, contact [email protected] and we will route you to the right person.