Security and data protection

How VitroVault is built and run

Your buyers take your word through us, so the questions they put to you are fair to put to us. These are the answers we are asked for most often, in enough detail to use in a questionnaire about your own suppliers.

Where your data lives

The three answers a data-protection reviewer asks for by name.

The EU, and only the EU

Everything runs in Ireland (AWS eu-west-1): your documents, your page, your event trail, the databases behind them and the logs that operate them.

Your documents are kept apart

Each organisation's documents live in storage of their own rather than in a shared pool with everyone else's, encrypted at rest under a managed key, and reachable only through the service.

In transit, always encrypted

HTTPS throughout, with HTTP Strict Transport Security set for two years across every hostname, including customer-branded ones.

What happens to a document you upload

Your trust page hands files to strangers on your behalf, so what sits between the upload button and a buyer opening it is worth setting out.

Scanned before it can be published

An upload lands in a holding area and is scanned for malware. Only a clean file is moved into your own storage and can be published or gated. Nothing is servable from the holding area.

Published is a decision, not a default

A document is a draft until somebody publishes it, and on Managed a second person can be required to approve first. Nothing you upload appears anywhere until that step.

Gated means gated everywhere

A document you mark as needing an agreement needs one on every route to it: the page, a direct link, an approved access request, the evidence export and a machine credential. The rule sits on the document, so there is no door that skips it.

Who can do what

Least privilege inside your organisation, and inside ours.

Roles, on every plan

Admins, contributors and reviewers, so the people who write are not automatically the people who publish. Included on Free, because a shared login is not a plan feature.

Two-factor where it matters, at your pace

Your organisation can require a second factor for the actions that change what the world can see: publishing, access, the team, deletion. You turn it on when your people have enrolled; nobody else's organisation is affected.

Support access appears on your log

Our support and operations staff reach your account through a separate, narrow interface, restricted by network and by named person. Every look lands on your event log with their name on it, alongside everything else that happened that day.

The trail, and how it can be checked

Every trust product has an activity log. This one can be verified rather than taken on trust.

Append-only, and sealed entry to entry

Who accepted which agreement version, when, and from where; who viewed and downloaded what; every publish, every grant, every change to the team. Each entry is sealed to the one before it, so altering or removing a past event breaks the seal on everything after.

Anchored outside the database

The sealed record is anchored separately and held under a lock with a fixed term, so the check does not depend on the same system that holds the entries.

Included on every plan

The full trail is on Free, with nothing withheld and no shorter history. It is the part a buyer’s reviewer inspects, so it is not something to sell back.

Email, and who receives it

Deliberately quiet, and the settings that decide it are yours per page.

You choose how access is granted

Per page: either accepting your agreement opens access immediately and you are told, or it holds for your approval and nothing opens until you say so.

Notifications go where you say

Set the address that receives access and agreement notices, per page. Your admins can approve an access request straight from the email, without signing in.

Your buyers are left alone

Publish a new version of your agreement and no one is emailed about it. Returning buyers are asked to accept the current text the next time they visit. The agreement is between you and them.

Where this fits your regulatory work

Where a trust page helps with obligations you already carry, set out plainly enough to check against your own advice.

UK GDPR and EU GDPR

For your trust page, you are the controller and we are your processor. Processing is in the EU, under a written agreement, with a published retention schedule and a route to erasure that you can run yourself. Buyer details captured at your gate (name, work email, company) are held for you and go when your account goes.

DORA, if your buyers are financial entities

They must keep a register of information about their ICT providers and evidence ongoing oversight rather than a one-off check. A maintained page with dated documents, a machine-readable summary and a record they can file gives them something to point at between reviews, instead of another questionnaire to you each quarter.

ISO 27001 and your certificates

If you hold certifications, they sit on the page with their scope and expiry, and go stale visibly rather than silently. Your coverage checklist maps the areas you are asked about to the documents that answer them. On Managed we check that mapping against your own documents rather than taking your word for it.

NIS2 and supplier due diligence generally

The pattern is the same wherever the regime comes from: someone must show they assessed their suppliers and kept doing so. Everything on your page is dated, everything gated is recorded, and both sides can prove what was disclosed and when.

A trust page is not a certification and does not make you compliant with anything. It gives you the evidence to show the work you have already done. Ask us about our own certification status and we will answer directly.

Reporting something to us

If you have found a security problem in VitroVault, or a trust page hosted with us that is being misused, tell us and we will act on it. Email security@vitrovault.com. Please include enough detail to reproduce it. We will not pursue anyone who reports a genuine issue in good faith.