| Transport and edge | TLS, HSTS, DDoS protection, security headers and tenant-scoped authorization on Cloudflare. | Public status and response headers. |
| Authentication | Email/password and passwordless links; Google/Microsoft OIDC becomes available when production provider credentials are connected. Platform console supports authenticator MFA and keeps the platform key as recovery. | Sign-in provider status is shown rather than implied. |
| Payment data | Stripe hosts card collection. Vectiform does not store raw card numbers. | Stripe-hosted checkout and signed webhooks. |
| Backups | Daily encrypted backups with 30-day rolling retention; auth credentials are scrubbed from portable exports. | Platform reliability center and restore procedures. |
| Recovery targets | RTO target: 24 hours. RPO target: 24 hours. These are operating targets, not contractual guarantees unless written into an order form. | Owner incident and backup guide. |
| Incidents | No material customer-data security incident is published as of July 28, 2026. Material incidents will be posted here with scope and remediation. | This dated incident history. |