security

Security

Your Data, Protected

Security engineered into every layer of the Vermoon platform: encryption, per-tenant isolation, human oversight and full traceability.

lock

AES-256 Encryption

database

EU-Hosted Database

supervisor_account

Human Oversight

receipt_long

Full Audit Trail

lock

Data Encryption

All data is encrypted in transit using TLS and at rest using AES-256 on our cloud infrastructure. Access tokens for connected accounts are additionally encrypted at the application layer before being stored.

verified_user

Certified Infrastructure

Vermoon runs on leading cloud providers whose platforms hold SOC 2 Type II and ISO 27001 certifications. Vermoon itself does not yet hold its own certification: we inherit these infrastructure controls and are building our formal security programme on top of them.

shield

GDPR & EU AI Act

We process personal data under the General Data Protection Regulation, applying data minimisation and purpose limitation. We are working with external legal counsel on a formal compliance programme covering both the GDPR and the EU AI Act.

public

Data Residency

Our production database is hosted in the European Union (AWS eu-west-1, Ireland). Requests sent to third-party AI model providers may be processed in the United States; we are formalising the corresponding international transfer safeguards with our legal advisors.

admin_panel_settings

Access Controls & Tenant Isolation

Each customer's data is isolated at the application layer: every database query is scoped to that customer's tenant. Access follows role-based control with least privilege, production access is restricted to a minimal set of authorised people, and agent activity is recorded in auditable logs.

emergency

Incident Response

Application errors and security-relevant events are logged centrally and reviewed daily. We investigate incidents promptly and, where personal data is affected, notify our customers and the competent authority without undue delay, in line with the GDPR's 72-hour breach notification framework.

code

Secure Development

Every code change is reviewed by a person before reaching production, on protected branches with mandatory pull requests. Development and production environments are separated, and sensitive agent actions (spending budget, publishing content, sending offers) sit behind human approval gates.

bug_report

Responsible Disclosure

If you believe you have found a vulnerability in Vermoon, please contact us through our contact page. We review every report, work with you to resolve confirmed issues, and keep you informed along the way.

Have Security Questions?

We are happy to answer questions, share documentation and support your vendor assessment process.

Contact Us
Vermoon - Agentic AI