Most security pages are written by lawyers and read like furniture. Ours is written by the people who built the system. If a coach in your audience asks "what happens to my client data," this is the answer to forward.
us-east-2 on AWS infrastructure.securityheaders.com A-grade.user_id scoping. Multi-tenant Row Level Security (RLS) ships with v0.2 multi-trainer team accounts. Until then, every coach is a separately-deployed instance.The complete list. If we ever add or remove one, this page updates and we send a notice email to all coaches.
PCI-DSS Level 1SOC 1, SOC 2 Type IIUSA
Handles all card data, recurring billing, payouts. We never see card numbers. Stripe privacy policy →
SOC 2 Type IIAES-256 at restAWS us-east-2
All coach + client data lives here, encrypted at rest. Point-in-time restore available for last 7 days. Neon privacy policy →
SOC 2 Type IINo training on your dataUSA
Powers AI plan generation, AI meal scan, AI rest-day messaging. We send minimum context. Anthropic privacy policy →
SOC 2 Type IIDDoS protectionGlobal CDN
Hosts the static site + Netlify Functions for our API endpoints. Netlify privacy policy →
GDPR-compliantEU + USA
Sends welcome emails, billing notifications, lifecycle messages. Recipient email addresses only — no client training data ever sent. Brevo privacy policy →
Things we don't have yet, by category, with timeline:
If you find a security issue, email security@vantagedigital.dev directly. We respond within 24 hours, ship fixes for critical issues within 48 hours, and credit the reporter publicly (or anonymously, your call) on a vulnerability disclosure page once the fix ships.
We don't run a paid bounty program at v0.1, but we send a thank-you box of nice merch for verified valid reports. The bounty program lands in v0.3.
Anything stated here is binding. If we change a practice, this page updates within 7 days and active coaches get an email. The version history of this page is visible in our public Git repo at github.com/GildtheLily85/vantage-digital — you can see every revision.
If your coaching practice involves clients with sensitive metrics, money, or training data — these are the people you want building the platform.
Start Cadence — $299 setup See full capability audit