Security is not a feature.

It's the foundation everything else is built on. Here's exactly how we protect your data — and your users' data — at every layer.

Request a security reviewsecurity@vorht.com
Compliance

Certifications in progress

We are actively pursuing independent third-party certifications. Here's where we stand.

In progress

SOC 2 Type II

Independent audit of our security, availability, and confidentiality controls. We are working with accredited CPA firm Schellman & Company. Estimated completion: Q4 2026.

In progress

GDPR

EU General Data Protection Regulation compliance. Data Processing Agreement available upon request. We have appointed a Data Protection Officer and implemented data subject request workflows.

In progress

CCPA

California Consumer Privacy Act compliance. Privacy notice, data inventory, and consumer rights request procedures are implemented. Final legal review in progress.

Practices

How we protect your data

Encryption everywhere

All data is encrypted in transit via TLS 1.3. Data at rest uses AES-256. Passkeys use hardware-backed biometric encryption. Verification tokens are hashed, never stored in plaintext.

Zero plaintext credentials

We never store passwords, verification codes, or raw biometric data. Only cryptographic public keys are persisted. A database breach yields nothing an attacker can use to authenticate.

Infrastructure isolation

Production systems run in isolated VPCs with strict network segmentation. Database clusters are not publicly routable. All access goes through a bastion host with session recording.

Continuous monitoring

Every authentication event, admin action, and API call is logged to an immutable audit trail. Anomaly detection flags unusual patterns in real time — credential stuffing, geographic anomalies, rate spikes.

Regular penetration testing

Independent third-party security firms conduct penetration tests quarterly. Results are reviewed by our engineering leadership and remediated within SLA — critical findings within 24 hours.

Vulnerability disclosure

We maintain a responsible disclosure program. Security researchers can report vulnerabilities to security@vorht.com. We commit to acknowledgment within 48 hours and a fix timeline within 5 business days.

Infrastructure

Built on AWS. Hardened by design.

HostingAWS (us-east-1, eu-west-1, ap-southeast-1)
ComputeIsolated ECS Fargate containers per tenant
DatabaseRDS PostgreSQL with Multi-AZ, automated backups every 6 hours
CacheElastiCache Redis with encryption in transit and at rest
CDNCloudFront with field-level encryption for sensitive payloads
SecretsAWS Secrets Manager with automatic rotation every 30 days
LoggingCloudWatch with 365-day retention, immutable append-only
DDoSAWS Shield Advanced with 24/7 SOC response team

Responsible disclosure

If you discover a security vulnerability in Vorht, please report it to us privately. We take every report seriously and will respond within 48 hours.

security@vorht.com
Acknowledgment: 48hFix timeline: 5 business daysPGP key available