Your Security Comes First

Back to DebtVault

An honest look at the controls in place today, and the payment infrastructure still being evaluated.

How We Protect You Today

Data Encryption

We protect your data in transit and at rest. In transit means information is encrypted while moving between your browser, our app, and our service providers, so it cannot be read if intercepted. At rest means stored data is encrypted on servers and databases, so raw records are not exposed.

Access Controls

Access to customer data is restricted to authorized team members who need it to operate or support the platform. We use role-based permissions, authentication controls, and internal audit practices so access is limited and reviewed. We do not provide broad access to sensitive data.

Card Data

DebtVault uses encryption in transit, access controls, and established service providers for the functions currently enabled. DebtVault does not store raw card numbers when Stripe-hosted payment components are used.

Infrastructure Status

DebtVault is testing and evaluating third-party providers for liability data and direct creditor payments. A sandbox or development integration does not mean live customer money movement is available. Production providers will be identified when approved and launched.

During founding access, DebtVault does not move customer money. You continue paying your creditors through your creditor or bank.

Incident Response

If we identify a security incident, we follow a defined response process: contain the issue, investigate scope, remediate root cause, and communicate updates when required. We prioritize protecting customer accounts, restoring normal operations, and documenting improvements to prevent recurrence.

What DebtVault Does Not Do

  • We do not sell your data
  • We do not store your bank passwords
  • We do not move your money during founding access
  • We do not make financial decisions for you