Trust

Security and trust

Last updated 18 August 2026. This page is a scaffold pending legal review — not a substitute for counsel-approved terms.

This is the public trust page for VApentest. Customer-facing scan certificates (per organization) remain at /trust/<org> and the in-app trust center is signed-in only. Badges on the marketing site link here rather than implying a certification we have not published.

Compliance status

  • SOC 2 Type II — in progress. We will publish an attestation letter or a dated update here when a report is available. Do not treat marketing badges as a completed Type II audit.
  • ISO 27001 — in progress. No certificate is claimed until an accredited body issues one.
  • GDPR — we process customer and prospect data as described in the privacy policy. Data-processing agreements are available on request via legal@vapentest.com.

Encryption and hosting

Data is encrypted in transit (TLS) and at rest (AES-256 as used by the database and disk layer). Production is operated by CyberSilo. The precise hosting region will be listed here once confirmed with ops — until then, treat region as "to be published," not as a specific cloud AZ.

Subprocessors

  • Payment processing. Stripe — card data handled by Stripe, not stored on VApentest servers.
  • Email delivery. Transactional mail via the configured SMTP/Resend provider.
  • Bot protection. Cloudflare Turnstile on public auth forms when configured.
  • Optional analytics. Google Analytics, only after cookie consent.

Testing cadence

The product continuously tests customer-authorized targets. VApentest itself is reviewed through internal testing and periodic third-party assessments. Cadence and latest executive summary will be linked here when a report can be shared under NDA or publicly.

Report a vulnerability

Email security@vapentest.com. Our vulnerability disclosure policy describes expected timelines. For legal requests use legal@vapentest.com; for product questions use support@vapentest.com.