Security

Clear facts about the service and its security status.

Review the current infrastructure, account access, published project model, assurance limits, and responsible disclosure process.

Service details

This is the current public description of the systems that support Venzato accounts and published projects.

1

Application and database

The Venzato service is hosted on Fly.io. Account and project data uses Supabase with PostgreSQL.

2

Account sign-in

Users can sign in with an email code, Google, or Apple. SSO and SAML are not currently available.

3

Published projects

A published site uses a site-<id>.venzato.com address or a customer-owned domain.

4

Payments

Purchases can use the App Store, Google Play, or the web. Polar is the merchant of record for web payments.

5

Project management

Users create and edit projects in Venzato Studio. Published project features are managed from the project panel.

6

Security contact

Send suspected vulnerabilities to info@venzato.com. Send account support and general questions to info@venzato.com.

Current assurance status

The items below are stated directly so security and legal teams can evaluate the current service without assumptions.

Not certified

SOC 2 and ISO 27001

Venzato does not currently claim SOC 2 or ISO 27001 certification.

Not available today

DPA and contractual SLA

A Data Processing Addendum and a contractual uptime SLA are not currently offered.

No location choice

Data residency

Customers cannot currently select a data residency region.

Details not published

Encryption and backups

Venzato does not currently publish a formal encryption control statement or a customer-facing backup schedule. Ask before relying on a specific requirement.

Do not assume a certification, contractual control, backup objective, or data location that is not listed here.

Ask a security question

Responsible disclosure

Use the dedicated security address for vulnerability reports. Do not include unrelated personal data or account secrets in the first message.

What to include

  • A clear description of the issue
  • Steps to reproduce it
  • The affected page or feature
  • Potential impact
  • Screenshots or a proof of concept when useful

Safe testing rules

  • Do not access or modify data that does not belong to you
  • Do not use social engineering
  • Do not intentionally disrupt the service
  • Do not publish the issue before the team can investigate
  • Stop testing if it may affect another user

Venzato reviews reports sent to the security address and can follow up through the contact details you provide.

Email info@venzato.com