Workforce Exposure
Starts with admin-provided employee or work email identities. No employee passwords, endpoint agent, or mailbox access is required to begin.
VANTABLADE / SECURITY & TRUST
VantaBlade limits access by role and task, verifies protected actions, and makes source coverage clear across its security products.
DATA MINIMIZATION
Each product has a different input boundary. We keep those boundaries explicit.
Starts with admin-provided employee or work email identities. No employee passwords, endpoint agent, or mailbox access is required to begin.
Uses the submitted email for a point-in-time check against known public breach data.
Uses submitted identifiers, a verified purchase, and a report destination. Paddle handles primary payment processing; PayPal remains an alternative when checkout is available.
AUTHENTICATION & TENANT BOUNDARIES
Customer workspace access uses Supabase Auth and authenticated API requests.
Company context scopes customer data, with PostgreSQL Row Level Security and tenant-aware APIs supporting the boundary.
Access, plan limits, account changes, and protected operations are verified by VantaBlade services.
SECURE ACCESS
DeepScan separates payment, scan submission, status, and report access into controlled stages.
VantaBlade confirms payment before issuing one-time, expiring DeepScan access. Result links are private and report access is temporary.
PROVIDER & EVIDENCE BOUNDARIES
OPERATIONAL CONTROLS
CURRENT ASSURANCE LEVEL
We do not imply certifications or independently verified controls that we have not obtained. Controls may evolve with customer and operational requirements; the public claim will remain bounded by current evidence.