Customers trust us with their audience’s answers. This page says plainly what we do to protect them, and how to tell us if you find a problem.
How data is protected
- Encrypted in transit. Every connection to vaneit.com and to our database uses HTTPS (TLS). Browsers are told to use HTTPS only.
- Encrypted at rest by our infrastructure providers (see Subprocessors).
- Each customer’s data is kept separate by database access rules enforced by the database itself, not just by our app. Signed-in customers can only read their own vanes, answers and surveys.
- Visitors see one vane at a time. The widget reads a single live vane by its id through narrow functions. It cannot list other vanes, see who owns them, or download raw answers.
- Every public write is checked on the server: answers must match the vane’s options, numbers must be in range, text is length-limited and filtered, and each connection is rate-limited.
- No passwords to steal. Customers sign in with a one-time email link; we store no passwords.
- IP addresses are not stored. For rate limits we keep only a keyed hash of the IP, with a key that changes daily, deleted within 24 hours.
- Hardened website. Security headers and a strict content security policy limit what any page can load or send.
- Limited access. Only the founder has administrative access to production systems, protected by multi-factor authentication on each provider account.
How data is kept safe from loss
- Nothing is deleted by accident. Deleting a vane or survey moves it to Recently deleted for 30 days, where the customer can restore it. Answers cannot be edited or deleted through the app or the API.
- Every change is logged. An audit log records when vanes and surveys are created, changed, deleted, restored or removed, and by whom.
- Backups. We take encrypted backups of the database and uploaded images, stored separately from the live service, and we check that they open.
- Export any time. Customers can download all of their data from their account.
If something goes wrong
If a security incident affects customer data, we will notify affected customers without undue delay, and within 48 hours of confirming it, with what we know and what we are doing. We will notify authorities where the law requires.
Reporting a vulnerability
Please email contact@vaneit.com with the subject “Security” and enough detail for us to reproduce the problem. Give us a reasonable time to fix it before telling anyone else, and do not access other people’s data, degrade the service, or use automated scanners against it. We will reply, keep you updated, and credit you if you would like. We do not take legal action against good-faith research that follows these rules. Our security.txt has the same details.
What we do not claim
VANE it is a young product run by a small team. We do not hold our own security certifications such as SOC 2 or ISO 27001; our infrastructure providers hold theirs. If your organisation needs a security questionnaire answered, email us and we will help.