Our security commitments
We treat the data you trust us with as if it were our own — because increasingly, it is. Sandi's system holds membership records, financial receipts, ministry correspondence, and client work product. Every control on this page exists to protect that trust.
SOC 2 readiness: we follow AICPA Trust Services Criteria across the five categories (Security, Availability, Processing Integrity, Confidentiality, Privacy). Our internal control matrix and policies are audit-ready and reviewed annually.
Active controls
Data protection in detail
What we collect
We collect only what we need to provide the service and meet legal obligations. The full list is on our privacy page. Categories include: account credentials, payment metadata (we never store card numbers), content you create, and operational logs.
How we encrypt
All data in transit uses TLS 1.2 or higher. Confidential data at rest is encrypted with AES-256 (database column-level for high-sensitivity fields, full-disk for backups). Encryption keys are managed by our hosting providers' KMS, with separate keys for backups so old backups become unrecoverable when keys are rotated.
Where data lives
Primary application: United States (Vercel + Neon, US-East). Membership platform: Germany or US (IONOS, customer-selectable for EU residents). EU customers can request EU-only data residency under our DPA.
Retention
Active data lives as long as the account is active, plus a 30-day grace after cancellation. Backups age out per a published schedule. Receipts and other financial records are retained for 7 years (US tax law). Full schedule on the privacy page.
Vulnerability management
We run automated dependency scans on every code change (Dependabot for npm, Python pip-audit). Critical vulnerabilities are patched within 7 days; high severity within 30 days. Monthly review of all open advisories.
If you find a security issue, we want to hear about it. See responsible disclosure below.
Responsible disclosure
We welcome reports from security researchers. If you believe you've found a vulnerability:
- Email us at security@valuetovictory.com (use PGP if you have a key — we'll publish ours soon)
- Don't publicly disclose before we've had a reasonable chance to investigate (typically 90 days)
- Don't access data beyond what's needed to demonstrate the issue · don't pivot · don't exfiltrate
We commit to: acknowledge within 72 hours · provide a status update weekly · credit you in our security log if you'd like.
Out of scope: social engineering, physical security, denial-of-service, third-party services we don't operate. Otherwise, fair game.
What we don't store
- Payment card numbers — handled exclusively by Stripe (PCI-DSS Level 1 certified)
- Government-issued ID images unless explicitly required for a specific service
- Health information — we are not a HIPAA-covered entity
- Biometric data — we don't collect, even for MFA (TOTP only)
Audit & compliance posture
| Framework | Status | Last review |
|---|---|---|
| SOC 2 Type II readiness | Documented controls · audit prep ongoing | 2026-04-29 |
| GDPR | DSAR process · DPA template · subprocessor list live | 2026-04-29 |
| CCPA / CPRA (California) | Privacy notice · opt-out paths · "Do Not Sell" honored | 2026-04-29 |
| State breach laws (US 50) | Notification matrix · 72h SLA · counsel engagement plan | 2026-04-29 |
| PCI-DSS | Out of scope (Stripe-tokenized) | n/a |
| HIPAA | Not a covered entity | n/a |
Questions?
Operators · enterprise prospects · auditors: email security@valuetovictory.com for our full SOC 2 control matrix, subprocessor DPAs, or any specific control evidence.
Members & users with privacy questions: see our privacy notice or your account's privacy controls.