How we secure your data
Your data is encrypted in transit and at rest, and access is restricted on a least-privilege basis. Vyera holds no independent security certification.
Vyera holds business information about your company and the competitors you track, so the measures protecting it are set out in full in our Data Processing Agreement rather than described in general terms.
What is in place
| Area | Measure |
|---|---|
| Data in transit | Encrypted using TLS 1.2 or higher |
| Data at rest | Encrypted, including databases and file storage |
| Passwords | Stored using industry-standard one-way hashing |
| Integration credentials and OAuth tokens | Stored encrypted |
| Internal access | Least-privilege, role-based, with named individual accounts |
| Administrative and infrastructure access | Multi-factor authentication required |
| Environments | Production and non-production separated into different cloud accounts |
| Monitoring | Infrastructure logging, including audit trails of administrative actions |
| Backups | Taken regularly, with defined retention and tested restoration |
| Vulnerabilities | Managed through timely security patching and dependency updates |
| Personnel | Bound by confidentiality obligations, with access reviewed and revoked on role change or departure |
The full list is in Annex 2 of our Data Processing Agreement, which is the authoritative version.
Certifications
Vyera does not currently hold an independent security certification such as SOC 2 or ISO 27001. We would rather say that directly than imply a certification we do not have. Where you need assurance for a procurement process, our Data Processing Agreement sets out the measures we commit to contractually, and section 11 of it describes how we respond to audit requests.
What is your responsibility
Security is shared. Vyera protects the platform and the data in it. You are responsible for your own account: keeping credentials secure, controlling who you invite to your workspace, removing members who no longer need access, and telling us promptly at support@vyera.ai if you suspect unauthorised access.
You are also responsible for what you put into the Service. Vyera is not built to hold special category personal data, criminal offence data, or data relating to children, and our Terms do not permit you to submit it.
What it does not do
These measures do not make any system completely secure, and we do not claim otherwise. If a breach affecting your data occurs, we will notify you and the relevant authority where the law requires it. For our current uptime and incident-response commitments, see Service availability.
They also do not extend to systems outside Vyera. If you connect Slack, Search Console or Google Analytics, the security of those accounts is governed by those providers and by your own configuration of them.
Was this useful?
Related articles
- Our data processing agreement
Vyera's DPA is published at vyera.ai/dpa and is incorporated into the Terms automatically, so there is nothing to sign.
- Access controls and permissions
Workspace roles control access on your side. Two-factor authentication is available per member, and an audit log can be exported.
- Our subprocessors
Vyera uses eight subprocessors, listed below, and gives 30 days' notice before adding or replacing one.
- Reporting a security issue
Report a security issue to support@vyera.ai with what you found and how to reproduce it.
Still stuck?
Send this to the team and we will pick it up.