Security
How we protect customer and guest data.
Data in transit and at rest
- All traffic between client devices and Vidimo is encrypted with TLS 1.2 or above.
- Customer data is stored encrypted at rest in our managed Postgres instance and our object storage buckets.
- Backups inherit the same encryption-at-rest guarantees and are tested for restorability on a recurring schedule.
Access control
- Multi-factor authentication is required for every member of the Nuage team on Google Workspace, GitHub, Vercel, and AWS.
- Production access follows least privilege — engineers request short-lived elevated credentials per task instead of holding standing admin access.
- Application-layer access is tenanted by property: cross-tenant reads are blocked at the query layer by PowerSync sync rules and at the API layer by property-membership checks.
Vulnerability management
- Continuous dependency scanning runs on every commit through GitHub Advanced Security.
- Quarterly third-party vulnerability scans are scheduled and the results are triaged within five business days of delivery.
- Critical CVEs in dependencies we ship to production are patched within 48 hours of public disclosure where a fix is available; high-severity within seven days; medium within 30 days.
Incident response
We maintain an internal incident-response runbook that defines on-call rotation, severity levels, communication templates, and post-mortem expectations. Customers affected by a security incident will be notified without undue delay and, where applicable, within the timeframes required by the GDPR.
Sub-processors
The current list of sub-processors that may handle customer or guest data on our behalf is published at Sub-processors. We update this list when we add, replace, or remove a sub-processor.
Compliance roadmap
Vidimo is GDPR-aligned by design. We are working towards SOC 2 Type I attestation; a Type II window will follow once Type I controls have been operational for the required period. Customers with specific compliance questions can request our current security questionnaire responses.
Report a vulnerability
We take reports from external researchers seriously. Please contact us — we will acknowledge receipt within two business days, agree on coordinated disclosure timing, and credit researchers in our release notes where requested.
Email: security@vidimo.app