Security
Your Data, Protected
Security engineered into every layer of the Vermoon platform: encryption, per-tenant isolation, human oversight and full traceability.
AES-256 Encryption
EU-Hosted Database
Human Oversight
Full Audit Trail
Data Encryption
All data is encrypted in transit using TLS and at rest using AES-256 on our cloud infrastructure. Access tokens for connected accounts are additionally encrypted at the application layer before being stored.
Certified Infrastructure
Vermoon runs on leading cloud providers whose platforms hold SOC 2 Type II and ISO 27001 certifications. Vermoon itself does not yet hold its own certification: we inherit these infrastructure controls and are building our formal security programme on top of them.
GDPR & EU AI Act
We process personal data under the General Data Protection Regulation, applying data minimisation and purpose limitation. We are working with external legal counsel on a formal compliance programme covering both the GDPR and the EU AI Act.
Data Residency
Our production database is hosted in the European Union (AWS eu-west-1, Ireland). Requests sent to third-party AI model providers may be processed in the United States; we are formalising the corresponding international transfer safeguards with our legal advisors.
Access Controls & Tenant Isolation
Each customer's data is isolated at the application layer: every database query is scoped to that customer's tenant. Access follows role-based control with least privilege, production access is restricted to a minimal set of authorised people, and agent activity is recorded in auditable logs.
Incident Response
Application errors and security-relevant events are logged centrally and reviewed daily. We investigate incidents promptly and, where personal data is affected, notify our customers and the competent authority without undue delay, in line with the GDPR's 72-hour breach notification framework.
Secure Development
Every code change is reviewed by a person before reaching production, on protected branches with mandatory pull requests. Development and production environments are separated, and sensitive agent actions (spending budget, publishing content, sending offers) sit behind human approval gates.
Responsible Disclosure
If you believe you have found a vulnerability in Vermoon, please contact us through our contact page. We review every report, work with you to resolve confirmed issues, and keep you informed along the way.
Have Security Questions?
We are happy to answer questions, share documentation and support your vendor assessment process.
Contact Us