Security
Security, stated plainly
This page describes our actual practices. As we complete formal certifications and audits, we’ll publish them here — we don’t claim badges we haven’t earned.
Practices
What we do today
Data handling
Customer sites and content belong to the customer. We use your data to operate the product — not to train models for other customers, and never to resell.
Access control
Team roles and permissions govern who can edit, approve, and publish. Production access inside Vembase is restricted and audited.
Encryption in transit
All published sites and all platform traffic are served over HTTPS with modern TLS.
Backups & recovery
Site content and configuration are backed up regularly, with restore paths tested as part of normal operations.
Responsible disclosure
Found a vulnerability? Email [email protected]. We respond to good-faith reports and credit researchers who help us.
AI content controls
AI-generated content passes fact-review and editorial-approval steps before publishing. Customers control what ships under their name.
Certifications
Formal certification status (such as SOC 2 or ISO 27001) will be published on this page when audits are complete. If your procurement process needs details in the meantime, contact [email protected] and we’ll walk you through our current posture.