Legal · How we protect data

Security.

This page explains — in plain terms — how Visit Vanta is built to keep guest data safe. If you want deeper detail, our security team will walk any prospective customer through the technical architecture during a live call.

Last reviewed: August 26, 2026 Questions? legal@visitvanta.com

1. Architecture principles

  • Per-tenant isolation. Each business has its own logical database and its own encryption keys.
  • Least privilege everywhere. Engineers cannot access production customer data without a documented on-call request; audit logs are immutable.
  • Boring by design. We prefer well-worn tools over novelty. Managed Postgres, standard cloud infrastructure, mature libraries.
  • Assume breach. We build so a single compromise stays contained.

2. Encryption

  • In transit: TLS 1.3 with modern cipher suites; HSTS preloaded; certificate pinning on kiosk devices.
  • At rest: AES-256 for all customer databases and backups.
  • Keys: per-tenant, rotated every 90 days, managed via cloud KMS with hardware-backed roots of trust.

3. Identity & access

  • SSO via SAML/OIDC available for Portal customers on our team plan.
  • MFA is required for every Visit Vanta employee accessing production.
  • Role-based permissions in the Portal (Owner, Manager, Front Desk).
  • All admin actions are logged and exportable to your SIEM.

4. Application security

  • Static and dynamic analysis on every build; dependencies are continuously scanned.
  • Third-party penetration test annually and after any material architecture change.
  • Coordinated disclosure program at security@visitvanta.com — we acknowledge within 24 hours.

5. Hardware & kiosk security

  • Kiosk devices ship in kiosk-mode; no third-party app installs.
  • Local storage is minimal, encrypted, and automatically wiped after successful sync.
  • If a kiosk is stolen or lost, it can be remotely revoked from the Portal in under a minute.

6. Data handling

  • Backups are encrypted, geographically redundant, and retained for 30 days.
  • Data is deleted irrecoverably within 30 days of account closure.
  • No third-party analytics inside the Portal touches guest data. Product analytics use aggregate, anonymized events.

7. Compliance & certifications

We're actively pursuing SOC 2 Type II and ISO 27001. Interim documentation is available under NDA for enterprise prospects. Data protection compliance covers CCPA (California), GDPR (EU/UK) and equivalent regimes.

8. Incident response

Our on-call team is paged for any Sev-1 or Sev-2 event affecting check-in availability or data integrity. Customers affected by a confirmed incident are contacted within 24 hours of confirmation, with a written post-mortem to follow within seven days.

9. Reporting a vulnerability

Please email security@visitvanta.com. We do not require you to sign an NDA to disclose. We do not litigate good-faith security research. Reports acknowledged within 24 hours, triaged within three business days.

10. Contact

Security operations: security@visitvanta.com
General: info@visitvanta.com · +1 (551) 222 9609