How we protect your information

Before we ask you to trust our recommendations, we want you to understand how seriously we take your data. We assess security programs for a living — so we hold our own platform to the same standard we'd expect of any vendor handling our information.

Security and privacy are the default operating mode of our platform — not optional settings you have to switch on. Everything below describes how the platform actually works.

  • You own your data

Your intake responses and the assessments we generate from them belong to you. We act as a processor on your instructions, and we never claim ownership of your data or anything derived from it.

  • Your raw answers are read by our system — not our staff

Your intake is processed automatically by the platform. Our people don't routinely read it. On the rare occasion a person needs access — to support you, resolve an issue, or at your own request — it requires a named approver, a documented reason, and it is fully logged. The default is simple: no human reads your raw intake.

  • Your data works only for you — never for anyone else

Each customer's intelligence boundary is self-contained. Your information makes your assessments sharper over time, building context unique to your environment — and it stays there. We never use your data to train AI models, and never to improve our service for other customers. Nothing learned from your environment ever crosses into another.

  • Every access is authenticated and logged

Access to your data is authenticated, scoped strictly to your engagement, and recorded on every read. Your reports are presented through our secure portal — never emailed around as loose attachments.

  • Your data lives in controlled, encrypted systems

Your data is held in encrypted, access-controlled cloud infrastructure — encrypted in transit and at rest. We use three named subprocessors: Anthropic for AI processing — under commercial terms that your data is never used to train models — Google Cloud for hosting and storage, and ProCoders, our engineering partner, whose team administers the platform from Ukraine, Bulgaria, and Portugal under contractual confidentiality obligations, with access scoped to operational support and maintenance and logged on every read. We'll tell you if that list ever changes.

  • When you leave, your data leaves with you

While you're a subscriber, we retain your history so your assessments keep getting sharper for you. If you don't renew, everything — your data, your reports, your accumulated history — is permanently removed within 30 days. You can also request deletion at any time, and we'll complete it within 30 days across every system.

  • What we don't do

— We don't sell your data.

— We don't use it to train AI models.

— We don't use it to benefit other customers.

— We don't routinely read your raw intake.

— We don't share it outside our named subprocessors.

— We don't email your reports around as unsecured files.

  • You're in control

You can request access to, export of, or deletion of your data at any time. We're also working toward SOC 2 Type II, giving you independent assurance of the controls described here.

Questions from your security team are welcome — we're happy to walk through any of this in detail. Contact: privacy@vantisdi.com