1. Architecture principles
- Per-tenant isolation. Each business has its own logical database and its own encryption keys.
- Least privilege everywhere. Engineers cannot access production customer data without a documented on-call request; audit logs are immutable.
- Boring by design. We prefer well-worn tools over novelty. Managed Postgres, standard cloud infrastructure, mature libraries.
- Assume breach. We build so a single compromise stays contained.
2. Encryption
- In transit: TLS 1.3 with modern cipher suites; HSTS preloaded; certificate pinning on kiosk devices.
- At rest: AES-256 for all customer databases and backups.
- Keys: per-tenant, rotated every 90 days, managed via cloud KMS with hardware-backed roots of trust.
3. Identity & access
- SSO via SAML/OIDC available for Portal customers on our team plan.
- MFA is required for every Visit Vanta employee accessing production.
- Role-based permissions in the Portal (Owner, Manager, Front Desk).
- All admin actions are logged and exportable to your SIEM.
4. Application security
- Static and dynamic analysis on every build; dependencies are continuously scanned.
- Third-party penetration test annually and after any material architecture change.
- Coordinated disclosure program at security@visitvanta.com — we acknowledge within 24 hours.
5. Hardware & kiosk security
- Kiosk devices ship in kiosk-mode; no third-party app installs.
- Local storage is minimal, encrypted, and automatically wiped after successful sync.
- If a kiosk is stolen or lost, it can be remotely revoked from the Portal in under a minute.
6. Data handling
- Backups are encrypted, geographically redundant, and retained for 30 days.
- Data is deleted irrecoverably within 30 days of account closure.
- No third-party analytics inside the Portal touches guest data. Product analytics use aggregate, anonymized events.
7. Compliance & certifications
We're actively pursuing SOC 2 Type II and ISO 27001. Interim documentation is available under NDA for enterprise prospects. Data protection compliance covers CCPA (California), GDPR (EU/UK) and equivalent regimes.
8. Incident response
Our on-call team is paged for any Sev-1 or Sev-2 event affecting check-in availability or data integrity. Customers affected by a confirmed incident are contacted within 24 hours of confirmation, with a written post-mortem to follow within seven days.
9. Reporting a vulnerability
Please email security@visitvanta.com. We do not require you to sign an NDA to disclose. We do not litigate good-faith security research. Reports acknowledged within 24 hours, triaged within three business days.
10. Contact
Security operations: security@visitvanta.com
General: info@visitvanta.com · +1 (551) 222 9609