Application and database
The Venzato service is hosted on Fly.io. Account and project data uses Supabase with PostgreSQL.
Review the current infrastructure, account access, published project model, assurance limits, and responsible disclosure process.
This is the current public description of the systems that support Venzato accounts and published projects.
The Venzato service is hosted on Fly.io. Account and project data uses Supabase with PostgreSQL.
Users can sign in with an email code, Google, or Apple. SSO and SAML are not currently available.
A published site uses a site-<id>.venzato.com address or a customer-owned domain.
Purchases can use the App Store, Google Play, or the web. Polar is the merchant of record for web payments.
Users create and edit projects in Venzato Studio. Published project features are managed from the project panel.
Send suspected vulnerabilities to info@venzato.com. Send account support and general questions to info@venzato.com.
The items below are stated directly so security and legal teams can evaluate the current service without assumptions.
Venzato does not currently claim SOC 2 or ISO 27001 certification.
A Data Processing Addendum and a contractual uptime SLA are not currently offered.
Customers cannot currently select a data residency region.
Venzato does not currently publish a formal encryption control statement or a customer-facing backup schedule. Ask before relying on a specific requirement.
Do not assume a certification, contractual control, backup objective, or data location that is not listed here.
Ask a security questionUse the dedicated security address for vulnerability reports. Do not include unrelated personal data or account secrets in the first message.
Venzato reviews reports sent to the security address and can follow up through the contact details you provide.
Email info@venzato.com