Vantage

Trust & Security

Security at Vantage

We're a security company. That means we hold ourselves to a higher standard — for how we handle your data, your credentials, and your trust.

Credential Security

When you configure authentication for a scan target, your credentials are encrypted at rest using AES-256 and are never logged, never exposed in UI outputs, and never transmitted beyond the secure scan pipeline. Credentials are used exclusively to authenticate scan sessions — they are never stored in plaintext.

Each customer's credentials are isolated in separate encrypted stores. Vantage employees cannot access your credentials. Access is audited.

Data Isolation

Every Vantage customer operates in a fully isolated tenant. Your scan results, findings, targets, and credentials are inaccessible to other customers at the database level, enforced through row-level security policies — not just application-layer checks.

Scan data is retained for the duration of your subscription. You can delete your data at any time. We do not sell or share your data with third parties.

What We Scan — and What We Don't

Vantage sends HTTP requests to your verified target application only. Scan traffic never routes through third-party proxies. We verify target ownership before any scanning begins, ensuring you can only test applications you control.

Our scanner does not perform network-layer attacks, does not store response bodies beyond what is needed for vulnerability evidence, and does not retain full HTTP logs.

Our Security Posture

All data encrypted in transit (TLS 1.3) and at rest (AES-256)
Role-based access control with least-privilege enforcement
Full audit logging on all authentication and data-access events
Infrastructure hosted on AWS with VPC isolation
Dependencies scanned for known CVEs on every build
SOC 2 Type II — in progress, expected Q4 2026 (planned)
ISO 27001 — planned for 2027 (planned)

Responsible Disclosure

If you discover a security vulnerability in Vantage, we ask that you disclose it to us privately before making it public. We commit to:

  • Acknowledge your report within 48 hours
  • Provide a resolution timeline within 5 business days
  • Credit you publicly if you choose (with your permission)
  • Not pursue legal action against good-faith security researchers

Report vulnerabilities to: security@vantage-sar.com

Penetration Testing

We conduct internal security reviews of the Vantage platform on a continuous basis using our own tooling. We also engage third-party penetration testing firms for independent validation. Results of third-party assessments are available to enterprise customers under NDA.

Have a security question not answered here?

security@vantage-sar.com