Security and data protection

You are asking buyers to take your word through us

Which makes every question they put to you fair to put to us. This page is our answer to the ones we are asked most. It describes what the service actually does, so if you are filling in a questionnaire about your suppliers, you can copy from it.

Where your data lives

Three answers a data-protection reviewer asks for by name, and the reasoning behind each, so you can tell whether ours would survive your own review.

The EU, and only the EU

Everything runs in Ireland (AWS eu-west-1): your documents, your page, your event trail, the databases behind them and the logs that operate them.

Why it is built this way: a residency promise with an exception in it is not a residency promise. There is no US region in the path to fail over to, so there is no quiet transfer to discover later.

Your documents are kept apart

Each organisation's documents live in storage of their own rather than in a shared pool with everyone else's, encrypted at rest under a managed key, and reachable only through the service.

Why it is built this way: isolation you can describe in one sentence is worth more than access rules you have to reason about. It also means closing an account is a deletion rather than a search-and-remove.

In transit, always encrypted

HTTPS throughout, with HTTP Strict Transport Security set for two years across every hostname, including customer-branded ones.

Why it is built this way: your buyers arrive from links in emails and questionnaires. The first request is the one most likely to be plain HTTP, so it is the one that has to be refused rather than upgraded quietly.

What happens to a document you upload

Your trust page hands files to strangers on your behalf. What sits between the upload button and a buyer opening it matters more here than in most products.

Scanned before it can be published

An upload lands in a holding area and is scanned for malware. Only a clean file is moved into your own storage and can be published or gated. Nothing is servable from the holding area.

Why it is built this way: your trust page hands files to strangers on your behalf. A supplier who unknowingly passes on an infected PDF has caused exactly the incident their trust page exists to say could not happen.

Published is a decision, not a default

A document is a draft until somebody publishes it, and on Managed a second person can be required to approve first. Nothing you upload appears anywhere until that step.

Why it is built this way: the expensive mistake in this product is publishing something that should have been gated. That has to take a deliberate act by a person who can see what they are about to make public.

Gated means gated everywhere

A document you mark as needing an agreement needs one on every route to it: the page, a direct link, an approved access request, the export, and a machine credential. There is no door that skips the agreement.

Why it is built this way: we found one. Until August 2026 an approved access request opened agreement-gated material without the agreement, because the check sat on the ceremony rather than on the document. It now sits on the document.

Who can do what

Least privilege inside your own organisation, and inside ours. Including the part most suppliers never get told about: what our staff can see.

Roles, on every plan

Admins, contributors and reviewers, so the people who write are not automatically the people who publish. Included on Free, because a shared login is not a plan feature.

Why it is built this way: the alternative to giving a colleague their own account is that they use yours, and then your trail names the wrong person for the rest of the account's life.

Two-factor where it matters, at your pace

Your organisation can require a second factor for the actions that change what the world can see: publishing, access, the team, deletion. You turn it on when your people have enrolled; nobody else's organisation is affected.

Why it is built this way: a stack-wide switch would lock out every owner without a factor, so it would never be flipped. An organisation-level one gets used.

Our staff are not quietly in your account

Support and operations reach your account through a separate, narrow interface that is restricted by network and by named person, and every look lands on your event log with their name on it.

Why it is built this way: it replaced administrators working directly against the infrastructure, where every action carried far more power than the task needed and left a record only in our systems, not in yours.

The trail, and why it can be trusted

Every trust product has an activity log. The question worth asking is whether anyone could quietly change one, and how you would know.

Append-only, and sealed entry to entry

Who accepted which agreement version, when, and from where; who viewed and downloaded what; every publish, every grant, every change to the team. Each entry is sealed to the one before it, so altering or removing a past event breaks the seal on everything after.

Why it is built this way: a log that can be edited is a document, not evidence. A reviewer who doubts it should be able to check rather than to trust.

Anchored outside the database

The sealed record is anchored separately and held under a lock with a fixed term, so the check does not depend on the same system that holds the entries.

Why it is built this way: sealing entries to each other proves nobody edited one in the middle. Anchoring proves nobody replaced the whole chain.

It is never a plan feature

The full trail is on Free, with nothing withheld and no shorter history.

Why it is built this way: the trail is the part a buyer's reviewer inspects. Selling it back to the customers who can least afford it would make the cheap tier the least trustworthy one, which is the opposite of the point.

What we send, and what you can switch off

Email is where a trust product usually starts annoying people. Ours is deliberately quiet, and the noisy option is the one that is off by default.

You choose how access is granted

Per page: either accepting your agreement opens access immediately and you are told, or it holds for your approval and nothing opens until you say so. Notifications go to an address you nominate, not to whoever happens to be an admin.

Why it is built this way: some suppliers want to meet every buyer, and some want the page to do the work. Choosing for them makes one of the two groups uncomfortable in a way they may not notice until it matters.

Notifications go where you say

Access and agreement notices go to an address you nominate per page, not to whoever happens to hold an admin role that week.

Why it is built this way: the person who should see a buyer arriving is often not the person who set the page up. Sending to "the admins" means it reaches everyone slightly and no one properly.

We do not chase your buyers

Publish a new version of your agreement and nobody is emailed about it. Returning buyers are asked to accept the current text the next time they visit, and that is all.

Why it is built this way: the agreement is between you and them. Emailing a stranger about a change to somebody else's contract, using an address they gave for one document, is not ours to do.

Where this fits your regulatory work

We are not a compliance certificate and do not sell one. What follows is where a trust page genuinely helps with obligations you already carry, stated plainly enough that you can check it against your own advice.

UK GDPR and EU GDPR

For your trust page, you are the controller and we are your processor. Processing is in the EU, under a written agreement, with a published retention schedule and a route to erasure that you can run yourself. Buyer details captured at your gate (name, work email, company) are held for you and go when your account goes.

Why it is built this way: the awkward question in this product is the buyer's data, not the supplier's. They are a third party who came to read something, so the least we can do is keep exactly what the gate needed and nothing more.

DORA, if your buyers are financial entities

They must keep a register of information about their ICT providers and evidence ongoing oversight rather than a one-off check. A maintained page with dated documents, a machine-readable summary and a record they can file gives them something to point at between reviews, instead of another questionnaire to you each quarter.

Why it is built this way: the burden lands on the financial entity, so the supplier who makes it easy is the one that keeps the contract. The evidence record exists because their file, not your page, is where their obligation is discharged.

ISO 27001 and your certificates

If you hold certifications, they sit on the page with their scope and expiry, and go stale visibly rather than silently. Your coverage checklist maps the areas you are asked about to the documents that answer them. On Managed we check that mapping against your own documents rather than taking your word for it.

Why it is built this way: a certificate PDF attached to an email is a claim about a moment. What a reviewer actually wants to know is whether it is still valid today, which is a question only a maintained page can answer.

NIS2 and supplier due diligence generally

The pattern is the same wherever the regime comes from: someone must show they assessed their suppliers and kept doing so. Everything on your page is dated, everything gated is recorded, and both sides can prove what was disclosed and when.

Why it is built this way: we would rather build the one thing every regime asks for than a checkbox per regime that has to be redone when the next one arrives.

None of this makes you compliant with anything, and we do not claim it does. It gives you the evidence to show the work you have already done. Our own certification status is a question we will answer directly if you ask, rather than imply here.

Reporting something to us

If you have found a security problem in VitroVault, or a trust page hosted with us that is being misused, tell us and we will act on it. Email security@vitrovault.com. Please include enough detail to reproduce it. We will not pursue anyone who reports a genuine issue in good faith.