Skip to content

Security and compliance

The legal terms are the Terms of Service. Personal-data handling is the Privacy Policy. This page is a developer summary of those documents and of behavior implemented in the product. It is not a certification, a data processing agreement, or a substitute for reading them. It does not promise that data stays in a particular country, and it does not state a contractual service level. A data processing agreement is available on request via vulnify.io/contact.

Vulnify is designed to store action metadata and not the contents of your records. Metadata includes the agent, action, resource, destination, record counts, timestamps, risk results, review decisions, and notes.

Optional content on a check is scanned for sensitive data and is not stored. Findings can be stored as detector names and LGPD categories. See Risk engine.

Do not send content you are not allowed to share. You keep the rights to data you submit. Vulnify’s license to process it is limited to providing and securing the service.

Account data is name, work email, password hash, organization name, role, and MFA state. Passwords and API keys are stored only as hashes. Security data includes IP address, request logs, and API key identifiers and last-use time.

The session is not a token in browser storage. The API sets two cookies, __Host-vln_at (access, about 15 minutes) and __Host-vln_rt (refresh, up to 30 days). Each is HttpOnly and Secure, with Path=/, SameSite=Lax, and no Domain attribute. Page scripts cannot read them. For one version the API still accepts the previous names vln_at and vln_rt. Those names are then removed.

Logout is POST /auth/logout. The response sends Clear-Site-Data: "cookies", "storage", expires __Host-vln_at, __Host-vln_rt, and the previous names, and invalidates the access token immediately.

Local storage keeps the language preference and a flag that a session may exist. That flag is not the session token. The app does not use advertising cookies, and it does not use analytics cookies. The marketing site at vulnify.io loads cookieless Cloudflare Web Analytics. The app at app.vulnify.io does not load that beacon.

Error diagnostics are sent only when monitoring is configured. For the app, that is only if a Sentry data source is set at build time, without session replay and without personal data by default, with email addresses, query strings, and authorization and cookie headers removed. For the API, that is only if monitoring is configured, and without the contents of your records.

The service runs in the United States. This page does not promise that data stays in a particular country. Vulnify does not sell personal data.

Parties that process data for the product or the marketing site:

  • Railway: application hosting and PostgreSQL, in the United States.
  • Resend: transactional email, the contact-form alert, and the bounce and complaint suppression list.
  • Stripe: subscription payments.
  • Sentry: error diagnostics for the app and the API, only when configured, without record contents and without session replay on the app.
  • Cloudflare: cookieless Web Analytics on the marketing site. The app does not load that beacon. Cloudflare also provides object storage (Cloudflare R2) for encrypted database backups. That data is encrypted database backups (all customer data in encrypted form), on Cloudflare’s global infrastructure. No specific region is promised. Cloudflare only holds encrypted files it cannot read.
  • GitHub: source code and continuous integration. It does not store the customer database.
  • Amazon Route 53: DNS only. It does not store customer records.

The privacy policy states that the United States has no adequacy decision for Brazil, and that where LGPD article 33 requires a safeguard the mechanism is the ANPD standard contractual clauses or another mechanism in that article. The same policy says it does not claim those clauses are already signed with every provider.

Decision events are deleted automatically after your plan’s retention window (Developer 7 days, Team 30 days, Business 365 days). The deletion job runs regularly. Enterprise retention follows your contract; there is no automatic deletion unless agreed. When an event is deleted, its audit-log entry (the decision, risk score and related metadata) is kept for as long as the organization exists, because the audit log is append-only. Deleted data can remain in encrypted backups for up to 30 days. See Plans and GET /public/plans.

The privacy policy notes that the Marco Civil da Internet (article 15) requires an application provider to keep application access logs for 6 months, and that Vulnify does not keep a separate 6-month archive of those logs. Request logs follow the hosting provider’s retention.

After the account or the organization is deleted, customer data is removed from the running service, except what the law requires Vulnify to keep. That exception is about the live service.

The production database is backed up automatically every day at 03:00 BRT (Brasília time). Each backup is encrypted with age before it leaves the database host. The decryption key is held only by Vulnify. The encrypted files are stored in Cloudflare R2. Cloudflare only holds those encrypted files and cannot read them. Backups are kept for at most 30 days, then deleted automatically. Deleted data can remain in a backup until that copy expires, at most 30 days. A restore of a full copy of the production database was tested on 2026-10-02, with row counts verified for every table. Restore drills are scheduled monthly. See Your data (export and deletion).

Contact-form leads are deleted after 12 months. The email suppression list is kept so a bounced or complained address is not mailed again. Account and organization deletion do not remove either of those.

Decisions are appended to a per-organization SHA-256 hash chain. Verification recomputes the chain and reports the first mismatch. You can run that check in the app. Owners and admins can download recent security events from Compliance as a JSON or CSV export. That download is not in the public OpenAPI document. See Audit log.

Webhook deliveries are signed with HMAC-SHA256. See Webhooks.

  • Measures in use include tenant isolation, hashed passwords, hashed API keys, an encrypted credential vault, access control, optional MFA, and a hash-chained audit log.
  • A password is at least 8 characters. The service rejects common or known passwords using a local list. Registration and password reset report that refusal as “Password is too common”. In Settings → Security, Change password sends POST /auth/change-password and signs out the other sessions.
  • API keys can be bound to one agent and restricted by source IP.
  • MFA can be turned on for an account. The product does not enforce MFA for a whole organization. When MFA is on, signing in and confirming a deletion require a current authenticator or recovery code, and approving a high or critical review asks for a fresh code.
  • Owners and admins manage keys, Slack, and webhooks.

No system is perfectly secure. The privacy policy says affected parties and authorities are notified of incidents as required by law.

The app builds framework reports from live evidence: inventory, policies, enforcement, monitoring, and the audit chain. Controls referenced in the product include:

Id Evidence the product describes
INV-1 AI agents inventoried.
POL-1 Access policies defined and enabled.
AUD-1 Hash-chained audit trail.
ENF-1 High-risk actions blocked or reviewed.
MON-1 Monitoring and anomaly detection.
LGPD-6 Records of processing and auditability of automated decisions.
ISO-A.6 Risk treatment through policies and enforcement.
NIST-MEASURE Per-event risk score from 0 to 100, with reasons, and baselines.
EU-LOG Append-only, hash-chained log of high-risk AI system use.

The public SDKs state that this evidence maps to LGPD, ISO/IEC 42001, NIST AI RMF, and the EU AI Act, and that the mapping is not a certification. These docs repeat that limit. A report score in the app is the product’s own view of which controls have evidence. It is not an attestation from those frameworks.

Decisions are an aid. In monitor mode nothing is blocked. You choose fail-open or fail-closed in the SDK, and you are responsible for reviewer decisions.

The encarregado (data protection officer, LGPD article 41) is Giovanni Zadinello, privacy@vulnify.io. That mailbox does not receive mail yet. A second channel is vulnify.io/contact.

Under the LGPD (article 18) and, where it applies, the GDPR, you can request confirmation, access, correction, anonymization, portability, deletion, information about sharing, and revocation of consent, and you can object. Exporting your data, and deleting an account or an organization you own, is self-serve in the app. See Your data (export and deletion). Correction, and any request that screen does not perform, goes to privacy@vulnify.io or through vulnify.io/contact. If the data sits in a customer’s workspace, Vulnify may direct the request to that customer. You can also complain to the ANPD or your local authority.

The service is for businesses and is not directed at people under 18.

  • Send metadata, not record bodies, unless you have a reason to scan content and you are allowed to.
  • Prefer failMode: 'closed' unless an outage must let the action through.
  • Keep API keys and webhook secrets out of models, logs, and git.
  • Verify webhook signatures on the raw body before you trust a delivery.
  • Run the action only when finalDecision is ALLOW. In monitor mode that matches the recorded decision. After a review, decision stays REVIEW and finalDecision moves.

Last updated October 3, 2026.

  • October 3, 2026. Backups: confirmed daily encrypted backups stored in Cloudflare R2, kept up to 30 days; Cloudflare added as backup storage subprocessor. Restore-test wording made precise. Event retention: rollout caveat, audit-log summary, Enterprise, backups.
  • October 3, 2026. Event retention phase 2 is live. Decision events are deleted automatically after the plan window. The rollout caveat is removed.
  • October 3, 2026. Password change is in Settings → Security and signs out other sessions. The compliance evidence download is a JSON or CSV export.