Security at Vyndarix
Enterprise-grade security is at the core of everything we do. We protect your data with the same rigor that we help you protect against fraud.
Testing and standards
- Penetration testing
- CompletedIndependently tested by a CREST-accredited firm, with a clean result.
- GDPR and UK GDPR
- CompliantEU and UK data protection, with DPAs and standard contractual clauses available.
- SOC 2
- Framework alignedControls designed to the SOC 2 Trust Services Criteria for security, availability and confidentiality. Independent audit on our roadmap.
- ISO 27001
- Framework alignedInformation security management aligned with ISO 27001.
- PCI DSS
- Designed to requirementsPayment card data handled in line with PCI DSS requirements.
Regulatory detail is on our compliance page.
How we protect your data
The controls that apply to every customer, from encryption to audit logging.
Encryption
All data encrypted in transit (TLS 1.3) and at rest (AES-256). End-to-end encryption for sensitive communications.
Authentication
Multi-factor authentication, SSO/SAML support, and role-based access controls for enterprise security.
Infrastructure
Cloud infrastructure with controls designed to SOC 2, and redundancy across multiple availability zones.
Monitoring
Continuous monitoring with real-time threat detection and automated incident response.
Data protection
Data isolation, secure backups, and retention policies aligned with regulatory requirements.
Access control
Principle of least privilege, regular access reviews, and comprehensive audit logging.
Security practices in detail
Data security
Encryption standards
- TLS 1.3 for all data in transit with perfect forward secrecy
- AES-256 encryption for all data at rest
- Customer-managed keys available for enterprise customers
- Hardware Security Modules (HSM) for key management
Data handling
- Data isolation between customers at application and database level
- Automated backups with point-in-time recovery
- Secure data deletion upon contract termination
- Data residency options for regulatory compliance
Infrastructure security
Cloud infrastructure
- Hosted on enterprise-grade cloud infrastructure
- Multi-region deployment for high availability
- Auto-scaling to handle traffic spikes
- High availability architecture for enterprise customers
Network security
- Web Application Firewall (WAF) protection
- DDoS mitigation at network edge
- Private VPC with network segmentation
- IP allowlisting for API access control
Application security
Secure development
- Secure SDLC with security reviews at each stage
- Static and dynamic analysis of all code
- Dependency scanning for vulnerable libraries
- Independent penetration testing by a CREST-accredited firm, with a clean result
Authentication and authorization
- Multi-factor authentication (MFA) required for all accounts
- SSO integration with SAML 2.0 and OIDC
- Role-based access control (RBAC) with fine-grained permissions
- Session management with automatic timeouts
Security operations
Monitoring and detection
- Continuous security monitoring with automated alerting
- SIEM integration for centralized log analysis
- Anomaly detection using machine learning
- Real-time alerting for security events
Incident response
- Documented incident response plan with defined escalation
- Regular tabletop exercises to test procedures
- Customer notification within 72 hours of confirmed breach
- Post-incident review and remediation tracking
Vulnerability disclosure
We take security vulnerabilities seriously. If you believe you've found a security issue in our products or services, we encourage responsible disclosure.
Report a vulnerability
Please email security reports to security@vyndarix.com.
We commit to acknowledging reports within 24 hours and working with researchers to resolve issues promptly. We do not pursue legal action against researchers who follow responsible disclosure practices.
Have security questions?
Our security team is available to answer questions and provide additional documentation for enterprise evaluations.
