The security principles every VantageVault service is built to.
Any service that stores user content encrypts it on the client before it leaves the device. Plaintext and private keys stay local, so operators cannot read what users store. This is the target for every storage service; each service’s current status is listed on the Projects page.
Frontend and backend code avoids heavy third-party frameworks. A small codebase is easier to audit and reduces supply-chain risk. Where an external service is worth the trade-off, such as managed authentication, it is chosen deliberately and disclosed.
Services use several independent layers: row-level access rules in the database, least-privilege permissions, rate limiting, firewalling and monitoring. No single layer is trusted to hold on its own.
A security claim is published only after it has been tested. Every service is checked against its own access rules before launch, and findings are fixed before new features ship.