VintageModeling
Security

What we hold, and what we refuse to.

If you are putting Vintage through vendor risk, this is the short version: what happens to a loan file, where it lives afterward, who can reach it, and what never arrives in the first place. Every statement describes how the product works today.

Data we refuse to hold

The strongest control is the data that never arrives. Sensitive information is removed on your own computer, before a file is uploaded.

When you choose a file, Vintage scrubs it in your browser. Columns identified as personal information are dropped. The Loan ID and the Tax ID are replaced with one-way scrambled values that cannot be turned back into the originals. Only the scrubbed file is uploaded, so the backend never receives raw personal information, raw loan IDs, or raw tax IDs.

The server adds a safety net on top of that. During analysis it can re-scan a sample of the already-scrubbed values, and a column it detects as still looking like personal information is automatically excluded from mapping and shown to you with the reason. It is a backstop, not the protection: the browser scrub, with your own review, is the protection.

Where your data lives

Uploaded data stays in United States infrastructure operated by a small, named set of providers.

  • In transit and at rest.Everything is served over TLS. Uploaded files, the database, and backups sit on infrastructure that encrypts them at rest.
  • The providers that hold it.Cloudflare runs the application and stores uploaded files. Neon hosts the database. Resend delivers transactional email such as invitations and password resets. A complete sub-processor list is available on request.
  • Automated recognition.To suggest a mapping for your columns and to run the PII re-scan described above, Vintage sends a bounded sample of the already-scrubbed column names and values to Anthropic's API. Whole files are never sent, and raw personal information cannot be sent because it never reached the server. If that service is unavailable, mapping falls back to matching column names and the re-scan simply does not run.

Tenant isolation and access

Every portfolio, upload, and field belongs to exactly one organization, and that boundary is enforced on the server.

  • Organization scope.Vintage never shows one organization's data to a person who is not a current member of it. Every data request is scoped to the caller's active organization and checked on the server, not merely hidden in the interface.
  • Enforced roles.Three roles are enforced: admin, editor, and viewer. A viewer is read-only, and the server refuses a viewer's writes rather than only hiding the controls. A new invitee defaults to viewer, the most limited role.
  • Network access.An organization can optionally restrict access to an allowlist of IP addresses and ranges: IPv4 or IPv6, single addresses or CIDR ranges. The allowlist is enforced by the API, and the product refuses to save one that would lock out the admin's own current address.
  • Sign-in.Email verification is required at sign-up: the product sends a six-digit code, and the account cannot be used until it is entered. A password reset link expires after an hour, and completing a reset signs out that account's other sessions.

Retention and provenance

What you uploaded is the durable record. It is kept so results can be audited and recomputed, and every number can be traced to where it came from.

  • Deletion and retention.Deleting an upload removes it from your active portfolio, and the portfolio is recomputed from what remains. The deleted file's values are permanently purged ninety days later. Data you have not deleted is retained as the audit basis for the figures built from it.
  • Provenance.Every value in the portfolio traces back to the upload, file, row, and source column that supplied it.

Certifications

Vintage does not hold a SOC 2 report today. We would rather say so here than have you find out three weeks into a review. What we do instead: answer your questionnaire directly, in writing, and tell you plainly which controls are in place and which are not.

Start a review

Send your vendor risk assessment or security questionnaire to the address below, or start a conversation on the contact page. We answer them ourselves.