Security
Last updated August 1, 2026
We take the security of your data seriously. This page describes the measures we use to protect VRsion Cards and your information.
Infrastructure
- Hosted on Vercel with HTTPS/TLS encryption for all traffic in transit.
- Data stored in a managed Postgres database (Neon) with encryption at rest.
- File uploads (photos, logos, covers) stored in Vercel Blob with access controls.
Application security
- Passwordless sign-in using one-time codes delivered by email — no passwords to leak.
- Server-side authorization on every account, card, lead, and billing operation.
- Rate limiting on public endpoints (lead capture, sign-in) to prevent abuse.
- Input validation and parameterized queries to prevent injection attacks.
Payments
Payments are processed by Stripe. Your full payment card details never touch our servers — they go directly to Stripe, which is PCI-DSS Level 1 certified. We store only your Stripe customer and subscription identifiers.
Data access
Access to production systems and data is limited to authorized personnel on a least-privilege basis. We do not sell your data or share it with third parties for advertising.
Reporting a vulnerability
If you believe you've found a security issue, please report it responsibly to security@vrsion.pro. We appreciate your help keeping VRsion Cards safe and will respond as quickly as we can.