Security at Every Layer
VantageKit protects your documents with layered encryption, granular access controls, and privacy-first data handling.
How We Protect Your Documents
Encryption and Infrastructure
- Data encrypted at rest and in transit
- Passwords hashed and unrecoverable
- Strict data isolation between teams
- SOC 2 certified hosting (Vercel, Supabase)
Access and Authentication
- Password-protected document links
- Email verification before viewing
- Allow and deny lists by email or domain
- Expiration dates and download controls
Privacy and Compliance
- IP addresses hashed before storage
- Minimal data collection by design
- Full activity audit trail
- GDPR, CCPA, and PDPL compliant
Document-Level Protection
Every document you share through VantageKit is protected by multiple layers of access control and traceability.
Password Protection
Require a password before anyone can view your documents. Passwords are hashed and never stored in plaintext.
Learn more about access controlEmail Verification
Require viewers to verify their identity through email before accessing your content. Know exactly who is reading.
Learn more about access controlAllow and Deny Lists
Control access by specific email addresses or entire domains with wildcard support. Block unauthorized viewers proactively.
Learn more about access controlLink Expiration and Download Control
Set expiration dates on shared links and control whether viewers can download your documents.
Learn more about access controlDynamic Watermarking
Every viewer sees a unique watermark. If a document leaks, trace it back to the exact viewer who shared it.
Learn more about watermarkingRole-Based Access Control
Assign Owner, Admin, Member, or Viewer roles to your team. Control who can create, edit, share, or view deal rooms.
Learn more about team managementPrivacy and Data Handling
VantageKit collects only what is necessary and protects everything it stores.
IP Address Hashing
Viewer IP addresses are hashed before storage. Raw IP addresses are never persisted in our database.
Privacy-Preserving Attribution
Viewer identity is stored as partial email hints, balancing traceability with privacy.
Data Retention Controls
You control how long your data is retained. Delete documents, links, and viewer data at any time.
GDPR Compliance
Data minimization, purpose limitation, and the right to erasure are built into the platform.
CCPA Compliance
Transparent data collection, opt-out support, and consumer rights under the CCPA.
PDPL Compliance
Consent-based processing, data subject rights, and breach notification under Middle East data protection laws.
Compliance and Roadmap
We are transparent about where we are today and where we are headed. Building trust means being honest about our security journey.
What We Do Today
- GDPR, CCPA, and PDPL compliant data handling
- Full activity audit trail for every document
- AES-256-GCM encryption at rest, TLS in transit
- Row-Level Security on every database table
- Hosted on SOC 2 certified infrastructure (Vercel, Supabase)
On Our Roadmap
Planned- SOC 2 Type 2 Certification2026
- ISO 27001 Certification2027
- Annual Penetration Testing Program2026
- Public Bug Bounty Program2027
Security FAQ
Have security questions?
Our team is happy to discuss VantageKit's security practices, provide documentation, or answer questions for your security review.
Contact Us