Last updated: August 23, 2026

Security & Trust

VertData powers financial-intelligence workflows for B2B customers. Security isn't a section on a page for us โ€” it's how we architect the platform. This page documents the controls, sub-processors, and practices we rely on.

๐Ÿ”’ TLS 1.3 in transit ๐Ÿ—๏ธ AES-256 at rest ๐Ÿ‡ช๐Ÿ‡บ GDPR compliant ๐Ÿป CCPA/CPRA compliant ๐Ÿ›ก๏ธ SOC 2 Type II (in progress)

1. Data protection

Encryption

Access control

2. Infrastructure

VertData runs on hardened Linux servers in a US-based data center with 24/7 physical security, redundant power, and DDoS mitigation at the edge. Application backends are proxied behind Nginx with strict security headers (CSP, X-Frame-Options, Referrer-Policy).

Database backups run daily, are encrypted at rest, and are retained per our retention policy. Point-in-time recovery is available for the most recent 7 days of production data.

3. Sub-processors

We use a small set of vetted sub-processors to operate the platform. Each has signed a Data Processing Agreement (DPA) with us and is bound to equivalent security and privacy obligations.

Sub-processorPurposeRegion
SupabaseManaged Postgres, authentication, row-level securityUS (us-west-2)
StripePayment processing, subscription billingUS / global
ResendTransactional email deliveryUS
AnthropicAI-scored insight generation on non-personal record dataUS
CloudflareDNS, edge protection, DDoS mitigation (where enabled)Global
Google AnalyticsAggregated, anonymized website analyticsUS
HostingerUnderlying VPS infrastructureUS

We give customers advance notice of material changes to this list via the Privacy Policy revision log. If you're a customer with contractual notification requirements, email security@vertdata.com to be added to the sub-processor notification list.

4. Monitoring & incident response

5. Data minimization

VertData's core dataset is drawn from publicly available business, property, and professional records. We collect the minimum amount of customer account information needed to operate the service (email, hashed password, billing details processed by Stripe, and usage metadata). We don't sell contact data to third parties for marketing purposes unrelated to VertData's services.

6. Compliance program

7. Responsible disclosure

If you believe you've found a security vulnerability, please email security@vertdata.com with:

We commit to acknowledging valid reports within 3 business days and won't pursue legal action against good-faith researchers who follow this policy.

8. Data ownership

You own your data. Customer-uploaded data, saved lists, notes, and workspace configuration are your property. VertData's role is a processor acting on your instructions. See Terms ยง7 and the DPA for the full commercial terms.

Need enterprise-level security documentation?

Security questionnaires, SIG-Lite responses, penetration-test summaries, and signed DPAs are available on request. Email security@vertdata.com and we'll get back to you within one business day.