Security & Compliance

Your secrets are encrypted, never logged, and permanently deleted after use

Security Features

Encryption at Rest & in Transit

All secrets are encrypted before being stored using industry-standard cryptography. Your data is protected both at rest in Redis and in transit over HTTPS.

One-Time Access

Each secret can only be viewed once. The moment it's opened, it's permanently and irreversibly deleted from our servers — the link immediately becomes dead.

Optional Passphrase

Add a passphrase to your secret for a second layer of protection. Even if someone intercepts the link, they can't open the secret without the passphrase.

Automatic Expiration

Secrets automatically expire between 1 hour and 7 days, regardless of whether they were ever viewed. Expired secrets are permanently purged.

Compliance

Vanisec is designed to help organizations meet data security and privacy compliance requirements:

SOC 2

Supports SOC 2 security requirements around access control and data protection through ephemeral, encrypted storage.

ISO 27001

Aligned with ISO 27001 information security standards for managing sensitive data and controlling access.

GDPR

Meets GDPR principles of data minimization and the right to erasure — secrets are deleted automatically and cannot be recovered.

CCPA & HIPAA

Designed to support CCPA and HIPAA compliance for handling sensitive personal and health-related information.

Privacy & Data Handling

  • No Logging

    We never write your secrets to application logs, analytics systems, or any persistent storage beyond the ephemeral Redis cache used to serve them.

  • No Tracking

    We don't track your behavior, collect personal data, or use tracking cookies. Vanisec is designed to know as little about you as possible.

  • Permanent Deletion

    Once a secret is opened or expires, it is permanently and irrecoverably deleted. There are no backups, no snapshots, no way to retrieve it.

  • Open Source & Auditable

    Vanisec is fully open source. You don't have to take our word for it — read the code, audit our implementation, or run your own instance.

Learn More

Share a Secret Securely