Data location

  • Desktop secrets stay in the local credential vault (AES-256-GCM; DPAPI/Keychain where available).
  • Account email, entitlements, and device fingerprints are stored in our PostgreSQL database.
  • Payment card data is never stored by Vazhion — Dodo Payments is merchant of record.
  • Crash dumps are local-only and are not uploaded.

Transport & application security

  • TLS for public web and API in production; HSTS enabled.
  • Argon2id passwords, short-lived access tokens, hashed refresh tokens, rate limits.
  • Admin console is a separate origin with staff TOTP and IP allowlisting.

Privacy rights

Authenticated users can export or delete account data from the portal (GDPR/CCPA-style requests with SLA timestamps). See the Privacy Policy and DPA.

Subprocessors

  • Dodo Payments — payments, tax, invoices
  • Transactional email provider (e.g. Resend) — magic links and notices
  • Hosting provider for web/API and managed or self-hosted Postgres

Contact

Security: security@vazhion.com · Privacy: privacy@vazhion.com · Breach notification target: 72 hours after awareness.