Trust & Security
Security at Vantage
We're a security company. That means we hold ourselves to a higher standard — for how we handle your data, your credentials, and your trust.
Credential Security
When you configure authentication for a scan target, your credentials are encrypted at rest using AES-256 and are never logged, never exposed in UI outputs, and never transmitted beyond the secure scan pipeline. Credentials are used exclusively to authenticate scan sessions — they are never stored in plaintext.
Each customer's credentials are isolated in separate encrypted stores. Vantage employees cannot access your credentials. Access is audited.
Data Isolation
Every Vantage customer operates in a fully isolated tenant. Your scan results, findings, targets, and credentials are inaccessible to other customers at the database level, enforced through row-level security policies — not just application-layer checks.
Scan data is retained for the duration of your subscription. You can delete your data at any time. We do not sell or share your data with third parties.
What We Scan — and What We Don't
Vantage sends HTTP requests to your verified target application only. Scan traffic never routes through third-party proxies. We verify target ownership before any scanning begins, ensuring you can only test applications you control.
Our scanner does not perform network-layer attacks, does not store response bodies beyond what is needed for vulnerability evidence, and does not retain full HTTP logs.
Our Security Posture
Responsible Disclosure
If you discover a security vulnerability in Vantage, we ask that you disclose it to us privately before making it public. We commit to:
- Acknowledge your report within 48 hours
- Provide a resolution timeline within 5 business days
- Credit you publicly if you choose (with your permission)
- Not pursue legal action against good-faith security researchers
Report vulnerabilities to: security@vantage-sar.com
Penetration Testing
We conduct internal security reviews of the Vantage platform on a continuous basis using our own tooling. We also engage third-party penetration testing firms for independent validation. Results of third-party assessments are available to enterprise customers under NDA.
Have a security question not answered here?
security@vantage-sar.com