Security
Last updated: July 21, 2026
We take the security of your account and data seriously and use technical and organizational safeguards designed to protect it. This page summarizes our approach honestly. No system is completely secure, and we do not make absolute guarantees.
Our approach
Security is built into how VectorOS is designed and operated: we minimize the data we collect, scope access tightly, keep sensitive credentials server-side, and rely on established infrastructure providers rather than reinventing critical components.
Encryption in transit
Traffic between your device and VectorOS is served over HTTPS/TLS. Data is stored with our infrastructure providers, which apply encryption at rest to their managed storage.
Authentication
Accounts are protected by our authentication provider. Passwords are stored in hashed form, never in plain text, and sign-in requires a verified email address. Password reset is self-service and time-limited.
Account isolation
Each account’s records are scoped to that account using database access controls, including row-level security policies enforced at the database, so users access their own workspace data and not others’.
Access controls
Privileged credentials are held server-side and are never shipped to the browser. Access to production systems follows least-privilege principles, and administrative capabilities are limited to what is necessary to operate the service.
Trusted infrastructure
We build on established providers — Supabase (database, authentication, storage), Vercel (hosting), and Stripe (payments) — so core security controls are backed by teams that specialize in them. See our Trust Center for the full list.
Payments
Payment card details are handled by Stripe, a PCI-compliant payment processor. VectorOS never receives or stores full payment card numbers.
Protecting your account
You play an important role in keeping your account secure. We recommend that you:
- use a strong, unique password and a reputable password manager;
- never share your password or sign-in link, and sign out on shared devices;
- keep your email account secure, since it can be used to reset your password;
- review imported and AI-generated information before acting on it; and
- contact us right away if you notice anything unusual.
Continuous improvement
Security is ongoing, not a one-time state. We monitor for issues, keep dependencies and infrastructure current, and improve our controls over time as the product and threat landscape evolve.
Responsible disclosure
If you believe you have found a security vulnerability, please report it privately to vectoros.app@gmail.com rather than disclosing it publicly, and give us a reasonable opportunity to investigate and address it. We appreciate good-faith research and will not pursue action against researchers who act responsibly, avoid privacy violations and service disruption, and do not access or modify data that is not their own.
This page is part of the VectorOS Trust Center. Questions? Contact vectoros.app@gmail.com.