Security
Engineering controls for Vazhion accounts and the desktop app. This page is not a SOC 2 report.
Data location
- Desktop secrets stay in the local credential vault (AES-256-GCM; DPAPI/Keychain where available).
- Account email, entitlements, and device fingerprints are stored in our PostgreSQL database.
- Payment card data is never stored by Vazhion — Dodo Payments is merchant of record.
- Crash dumps are local-only and are not uploaded.
Transport & application security
- TLS for public web and API in production; HSTS enabled.
- Argon2id passwords, short-lived access tokens, hashed refresh tokens, rate limits.
- Admin console is a separate origin with staff TOTP and IP allowlisting.
Privacy rights
Authenticated users can export or delete account data from the portal (GDPR/CCPA-style requests with SLA timestamps). See the Privacy Policy and DPA.
Subprocessors
- Dodo Payments — payments, tax, invoices
- Transactional email provider (e.g. Resend) — magic links and notices
- Hosting provider for web/API and managed or self-hosted Postgres
Contact
Security: security@vazhion.com · Privacy: privacy@vazhion.com · Breach notification target: 72 hours after awareness.