Security & Compliance
Your secrets are encrypted, never logged, and permanently deleted after use
Security Features
Encryption at Rest & in Transit
All secrets are encrypted before being stored using industry-standard cryptography. Your data is protected both at rest in Redis and in transit over HTTPS.
One-Time Access
Each secret can only be viewed once. The moment it's opened, it's permanently and irreversibly deleted from our servers — the link immediately becomes dead.
Optional Passphrase
Add a passphrase to your secret for a second layer of protection. Even if someone intercepts the link, they can't open the secret without the passphrase.
Automatic Expiration
Secrets automatically expire between 1 hour and 7 days, regardless of whether they were ever viewed. Expired secrets are permanently purged.
Compliance
Vanisec is designed to help organizations meet data security and privacy compliance requirements:
SOC 2
Supports SOC 2 security requirements around access control and data protection through ephemeral, encrypted storage.
ISO 27001
Aligned with ISO 27001 information security standards for managing sensitive data and controlling access.
GDPR
Meets GDPR principles of data minimization and the right to erasure — secrets are deleted automatically and cannot be recovered.
CCPA & HIPAA
Designed to support CCPA and HIPAA compliance for handling sensitive personal and health-related information.
Privacy & Data Handling
No Logging
We never write your secrets to application logs, analytics systems, or any persistent storage beyond the ephemeral Redis cache used to serve them.
No Tracking
We don't track your behavior, collect personal data, or use tracking cookies. Vanisec is designed to know as little about you as possible.
Permanent Deletion
Once a secret is opened or expires, it is permanently and irrecoverably deleted. There are no backups, no snapshots, no way to retrieve it.
Open Source & Auditable
Vanisec is fully open source. You don't have to take our word for it — read the code, audit our implementation, or run your own instance.