Trust Center

Security

How we protect your data and the systems that hold it.

Last updated: 2026-04-29

Our security commitments

We treat the data you trust us with as if it were our own — because increasingly, it is. Sandi's system holds membership records, financial receipts, ministry correspondence, and client work product. Every control on this page exists to protect that trust.

SOC 2 readiness: we follow AICPA Trust Services Criteria across the five categories (Security, Availability, Processing Integrity, Confidentiality, Privacy). Our internal control matrix and policies are audit-ready and reviewed annually.

Active controls

CC6 · Access
MFA on every admin path
TOTP-based multi-factor on every operator account. SMS-only is not accepted.
CC6 · Access
Least-privilege roles
Role-based access · quarterly access reviews · 24-hour deprovisioning SLA.
CC8 · Change
PR-gated production changes
Branch protection · CODEOWNERS-required review · CI gates · git-signed history.
A1 · Availability
Daily backups · quarterly restore drill
Hourly snapshots + daily fulls · 30-day hot retention · tested restores quarterly.
C1 · Confidentiality
TLS in transit · encrypted at rest
TLS 1.2+ enforced · AES-256 column-level encryption for sensitive data classes.
CC7 · Monitoring
Append-only audit log
Every authentication event, admin action, sensitive read, and webhook is logged with PII-scrubbed metadata.
CC9 · Vendors
DPAs with every subprocessor
Every vendor handling confidential data has a DPA in place · subprocessor list publicly maintained.
CC7 · Incident
72-hour breach notification
Documented IR plan · severity matrix · quarterly tabletops · 72h notification SLA.
P1 · Privacy
DSAR portal in your account
Access · export · correct · delete your data via /account/privacy · 30-day SLA.

Data protection in detail

What we collect

We collect only what we need to provide the service and meet legal obligations. The full list is on our privacy page. Categories include: account credentials, payment metadata (we never store card numbers), content you create, and operational logs.

How we encrypt

All data in transit uses TLS 1.2 or higher. Confidential data at rest is encrypted with AES-256 (database column-level for high-sensitivity fields, full-disk for backups). Encryption keys are managed by our hosting providers' KMS, with separate keys for backups so old backups become unrecoverable when keys are rotated.

Where data lives

Primary application: United States (Vercel + Neon, US-East). Membership platform: Germany or US (IONOS, customer-selectable for EU residents). EU customers can request EU-only data residency under our DPA.

Retention

Active data lives as long as the account is active, plus a 30-day grace after cancellation. Backups age out per a published schedule. Receipts and other financial records are retained for 7 years (US tax law). Full schedule on the privacy page.

Vulnerability management

We run automated dependency scans on every code change (Dependabot for npm, Python pip-audit). Critical vulnerabilities are patched within 7 days; high severity within 30 days. Monthly review of all open advisories.

If you find a security issue, we want to hear about it. See responsible disclosure below.

Responsible disclosure

We welcome reports from security researchers. If you believe you've found a vulnerability:

We commit to: acknowledge within 72 hours · provide a status update weekly · credit you in our security log if you'd like.

Out of scope: social engineering, physical security, denial-of-service, third-party services we don't operate. Otherwise, fair game.

What we don't store

Audit & compliance posture

FrameworkStatusLast review
SOC 2 Type II readinessDocumented controls · audit prep ongoing2026-04-29
GDPRDSAR process · DPA template · subprocessor list live2026-04-29
CCPA / CPRA (California)Privacy notice · opt-out paths · "Do Not Sell" honored2026-04-29
State breach laws (US 50)Notification matrix · 72h SLA · counsel engagement plan2026-04-29
PCI-DSSOut of scope (Stripe-tokenized)n/a
HIPAANot a covered entityn/a

Questions?

Operators · enterprise prospects · auditors: email security@valuetovictory.com for our full SOC 2 control matrix, subprocessor DPAs, or any specific control evidence.

Members & users with privacy questions: see our privacy notice or your account's privacy controls.

Home Privacy Terms Trust Center Subprocessors Status