VANTABLADE / SECURITY & TRUST

Security without inflated claims.

VantaBlade limits access by role and task, verifies protected actions, and makes source coverage clear across its security products.

Minimize dataVerify authorityRepresent uncertainty
01

DATA MINIMIZATION

Collect for the task, not for possibility.

Each product has a different input boundary. We keep those boundaries explicit.

Workforce Exposure

Starts with admin-provided employee or work email identities. No employee passwords, endpoint agent, or mailbox access is required to begin.

FreeScan

Uses the submitted email for a point-in-time check against known public breach data.

DeepScan

Uses submitted identifiers, a verified purchase, and a report destination. Paddle handles primary payment processing; PayPal remains an alternative when checkout is available.

02

AUTHENTICATION & TENANT BOUNDARIES

Access follows authenticated context.

AUTH

Authenticated workspaces

Customer workspace access uses Supabase Auth and authenticated API requests.

TENANT

Tenant-separated access

Company context scopes customer data, with PostgreSQL Row Level Security and tenant-aware APIs supporting the boundary.

CONTROL

Protected decisions stay on the server

Access, plan limits, account changes, and protected operations are verified by VantaBlade services.

03

SECURE ACCESS

Access is limited to the task at hand.

DeepScan separates payment, scan submission, status, and report access into controlled stages.

01Hosted checkout
02Payment confirmation
03Secure scan submission
04Result link
05Temporary report access

VantaBlade confirms payment before issuing one-time, expiring DeepScan access. Result links are private and report access is temporary.

PROVIDER & EVIDENCE BOUNDARIES

Absence is not manufactured certainty.

  • Provider availability is represented explicitly.
  • An unavailable provider is not treated as zero findings.
  • Point-in-time checks do not claim universal coverage.
  • Lack of a finding does not prove absence everywhere.
  • AI interpretation cannot create evidence.

OPERATIONAL CONTROLS

Lifecycle control remains server-side.

  • HTTPS for browser-to-service traffic
  • Rate limiting and restricted production origins
  • Server-only secrets and production test bypasses disabled by default
  • Durable job state and backend-controlled transitions

CURRENT ASSURANCE LEVEL

VantaBlade is not currently SOC 2 certified.

We do not imply certifications or independently verified controls that we have not obtained. Controls may evolve with customer and operational requirements; the public claim will remain bounded by current evidence.

SECURITY CONTACT

Security or privacy questions?

support@vantablade.io