Vintri Security & Trust Center
Trusting your organization's data with Vintri Technologies is an important decision, and we take that responsibility very seriously. Explore our controls and certifications to see how we keep your data safe.
Security Overview
How does Vintri® Technologies protect data?
User credentials are securely stored with our identity partners, Azure and Auth0. They are not reversible (hashed and salted).
All your data is encrypted in transfer and at rest.
Admin users can control employee data access via roles & permissions.
Customer support tasks are restricted to trained personnel.
Our service organizational controls (SOC) team continuously reviews and enforces our SOC policies.
Where and how is the data stored?
All customer data is stored in highly secure Azure data centers. These centers are ISO 27001 and SOC2 compliant.
The Azure data centers and network architecture are built to meet the requirements of the most security sensitive organizations.
Vintri’s Azure instances and data are located in the USA.
Who can access the data?
You, your employees, contractors, and suppliers have access to your data, based on the roles, project permissions, and attribute level data permissions you set for each user. Each user must login to view any information.
You can control who has access and what level of access is given to any employee, contractor, or supplier.
Our customer support staff will only access your data with your permission and at your request. Only employees who are trained and authorized can access the data.
Is the data backed up?
Yes, all customer data is securely backed up and encrypted.
Application development
Our Secure Software Development Life Cycle ensures that we use secure coding practices, static code assessments, senior level code reviews, and dynamic application testing to find exploits prior to any deployments to production.
We test our systems against the OWASP Top 10 standard at minimum to ensure code, configuration and architecture level security.
Application security monitoring
We use technologies to monitor exceptions, logs, and detect anomalies in our applications.
We collect and store logs to provide an audit trail of our application & activity.
How you can do your part
It is also important for you to guard against unauthorized access to your organization’s data by maintaining strong passwords and protecting against the unauthorized use of your own computer or device. Remember: you can control the safety of your password.
We will never ask you to disclose your password to us or anyone else, and you should not share it with anyone.
We recommend that your users change their passwords periodically.
A strong password contains a mix of numbers, letters, and symbols and is only used for one account.
Always log out when you use a computer you share with other people.
Compliance
SOC 2 Type II - Audited annually
Controls
Vintri maintains a comprehensive set of security controls covering all aspects of our operations.
Infrastructure Security
Cloud-native, multi-layered defenses. 24/7 monitoring, regular penetration testing, and automated patch management.
Product Security
Secure software development lifecycle (SDLC), code reviews, and automated vulnerability scanning and reporting.
Data & Privacy
End-to-end encryption, granular data access controls, and strict compliance with global privacy regulations.
Processes & Procedures
Formal IT policies and procedures cover physical security, logical access, operations, change control, and data communication. All teams must adhere to these policies, accessible via the company intranet.
Physical Security
All data is hosted by Microsoft Azure. Vintri employees have no physical data center access.
Organization Security
Background checks, security training, and strict access controls for all personnel. Zero-trust policies enforced.
Internal Security Procedures
Incident response plans, regular drills, and continuous improvement based on lessons learned and industry trends.
Encryption & Data Protection
All data types processed by vintriCORE are encrypted in transit and at rest. Configuration Data, Log Data, and samples of Customer Data are encrypted at rest in our databases, caches, and cloud storage.
Logical Access
Role-based access control ensures least-privilege access for employees and contractors. Access is managed and provisioned through cloud/SaaS systems with clear roles: Administrator, User, or No access.
Sub-Processors
Microsoft Azure & Auth0: Identity management
Cloudflare: Protection & CDN
Microsoft Azure: Cloud infrastructure & services
FAQ
How many security controls does Vintri have?
Vintri maintains a comprehensive set of security controls, covering all aspects of our technology, operations, and organizational processes.
How does Vintri manage employee access?
Vintri uses strict role-based access control for all infrastructure and SaaS systems, ensuring least-privilege access. Roles include Administrator, User, or No access, with all provisioning and deprovisioning managed centrally.
Are your employees trained in security best practices?
Yes. All employees complete mandatory security awareness training and regular refreshers.
What types of data are encrypted and how?
All data types, including configuration, log, and customer data, are encrypted in transit and at rest - across our databases, caches, and cloud storage.
Do Vintri employees have physical access to data centers?
No. All data is hosted in Microsoft Azure data centers, and Vintri employees do not have physical access. Vintri operates fully remotely.
Where is my data stored?
All customer data is stored in secure, geo-redundant data centers within the USA.
How do you handle data deletion requests?
We honor all data deletion requests promptly in accordance with applicable laws and regulations.

