Skip to main content
VantageKit

Security at Every Layer

VantageKit protects your documents with layered encryption, granular access controls, and privacy-first data handling.

How We Protect Your Documents

Encryption and Infrastructure

  • Data encrypted at rest and in transit
  • Passwords hashed and unrecoverable
  • Strict data isolation between teams
  • SOC 2 certified hosting (Vercel, Supabase)

Access and Authentication

  • Password-protected document links
  • Email verification before viewing
  • Allow and deny lists by email or domain
  • Expiration dates and download controls

Privacy and Compliance

  • IP addresses hashed before storage
  • Minimal data collection by design
  • Full activity audit trail
  • GDPR, CCPA, and PDPL compliant

Document-Level Protection

Every document you share through VantageKit is protected by multiple layers of access control and traceability.

Password Protection

Require a password before anyone can view your documents. Passwords are hashed and never stored in plaintext.

Learn more about access control

Email Verification

Require viewers to verify their identity through email before accessing your content. Know exactly who is reading.

Learn more about access control

Allow and Deny Lists

Control access by specific email addresses or entire domains with wildcard support. Block unauthorized viewers proactively.

Learn more about access control

Link Expiration and Download Control

Set expiration dates on shared links and control whether viewers can download your documents.

Learn more about access control

Dynamic Watermarking

Every viewer sees a unique watermark. If a document leaks, trace it back to the exact viewer who shared it.

Learn more about watermarking

Role-Based Access Control

Assign Owner, Admin, Member, or Viewer roles to your team. Control who can create, edit, share, or view deal rooms.

Learn more about team management

Privacy and Data Handling

VantageKit collects only what is necessary and protects everything it stores.

IP Address Hashing

Viewer IP addresses are hashed before storage. Raw IP addresses are never persisted in our database.

Privacy-Preserving Attribution

Viewer identity is stored as partial email hints, balancing traceability with privacy.

Data Retention Controls

You control how long your data is retained. Delete documents, links, and viewer data at any time.

GDPR Compliance

Data minimization, purpose limitation, and the right to erasure are built into the platform.

CCPA Compliance

Transparent data collection, opt-out support, and consumer rights under the CCPA.

PDPL Compliance

Consent-based processing, data subject rights, and breach notification under Middle East data protection laws.

Compliance and Roadmap

We are transparent about where we are today and where we are headed. Building trust means being honest about our security journey.

What We Do Today

  • GDPR, CCPA, and PDPL compliant data handling
  • Full activity audit trail for every document
  • AES-256-GCM encryption at rest, TLS in transit
  • Row-Level Security on every database table
  • Hosted on SOC 2 certified infrastructure (Vercel, Supabase)

On Our Roadmap

Planned
  • SOC 2 Type 2 Certification2026
  • ISO 27001 Certification2027
  • Annual Penetration Testing Program2026
  • Public Bug Bounty Program2027

Security FAQ

Have security questions?

Our team is happy to discuss VantageKit's security practices, provide documentation, or answer questions for your security review.

Contact Us