Legal
Security
Effective May 6, 2026
Starter template. This document was drafted from common SaaS patterns and has notbeen reviewed by counsel. Review with a lawyer before relying on it for live transactions, disputes, or regulatory compliance. Flag any clauses that don't match how Varosity actually operates.
Varosity is built with security-first defaults. This page summarizes our technical controls, data protection practices, and how to report a security vulnerability.
Encryption
- At rest: All database data is encrypted at rest (AES-256) by Supabase (hosted on AWS). Provider API keys stored in Varosity are encrypted with AES-256-GCM before being written to the database — Varosity holds the encryption key, not the provider keys in plaintext.
- In transit: All data in transit uses TLS 1.2 or higher. Vercel enforces HTTPS on all public endpoints.
- Bearer tokens: API tokens (
vsk_*) are stored as BLAKE3 hashes. The plaintext token is presented once at issuance and never stored.
Access Control
- Row-level security (RLS): All user data in the database is protected by Supabase Row-Level Security. Users can only access their own rows. There are no publicly accessible tables without explicit RLS policies.
- Least privilege: API tokens carry explicit scopes (e.g.
generate:video,brand:read). The backend validates scopes on every request. - MFA: Multi-factor authentication is required for all Varosity staff accounts on Supabase, Vercel, Stripe, and GitHub.
Infrastructure
- Hosting: Varosity runs on Vercel's Edge network (SOC 2 Type II certified).
- Database: Supabase Postgres with continuous point-in-time recovery (PITR) and automated daily snapshots. Supabase is SOC 2 Type II certified.
- Payments: Payment processing is handled entirely by Stripe (PCI DSS Level 1 certified). Varosity never stores payment card data.
- Generated media: Generated video, image, and audio files are stored in Cloudflare R2 with a 48-hour lifecycle. They are not retained by Varosity beyond 48 hours.
No Logging of Secrets
Varosity's logging policy prohibits logging of any secret material: no plaintext API tokens, no decrypted BYOK keys, no Stripe keys, no encryption keys. Structured logs contain only opaque user IDs, tool names, and performance metrics.
Vulnerability Management
- Automated dependency scanning via Dependabot on the GitHub repository.
- Critical CVEs (CVSS 9.0+) are patched within 7 days; high-severity within 30 days.
- All production changes go through peer code review before deployment.
Vulnerability Disclosure
If you discover a security vulnerability in Varosity, please report it responsibly:
- Email: security@varosity.ai
- Include a description of the vulnerability, steps to reproduce, and your assessment of the potential impact.
- We will acknowledge receipt within 48 hours and provide a remediation timeline.
- We ask that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to fix it.
We do not currently operate a formal bug bounty program, but we appreciate responsible disclosures and will acknowledge researchers in our changelog where appropriate.
Compliance Posture
Varosity maintains a SOC 2 readiness package and will pursue Type I certification on customer request. We are GDPR-compliant for EU data subjects — see our Privacy Policy and Subprocessor List.
For enterprise compliance inquiries, Data Processing Agreements, or security questionnaires, contact support@varosity.ai.