Vapus / Security
Trust, by design
Nothing leaves the vault without you
Health information is among the most sensitive data there is. Here is exactly how Vapus protects it, and, just as important, what it does not do.
What we do
- Encrypted in transit. Everything between your browser and Vapus uses HTTPS.
- Encrypted at rest. Records and files are encrypted on disk by our infrastructure provider.
- Access checked on every request. The server confirms who you are, and whether you may see that vault, each time.
- Private file storage. Documents are not public. Opening one uses a link that expires after 60 seconds.
- Granular delegate access. Log only, log and view, or full access, revocable at any time. Invites work once, for one email address.
- Expiring share links. Long random links with a hard expiry, read-only, and revocable. They show only what you selected, and never your file storage addresses.
- Its own infrastructure. Vapus runs in its own database project, separate from other Shoonya Origins ventures.
What we do not do
Not end-to-end encrypted
Vapus's servers can read your records in order to show them to you and to the people you share with. This is different from end-to-end encryption, where only you could read them. If we add end-to-end encryption, we will say so here.
- Vapus has not yet had an independent security audit or certification.
- No system is perfectly secure, and we cannot promise that a breach will never happen.
- If a breach affects your data, we will tell you as the law requires.
Where your data is handled
- Supabase: sign-in, database and file storage.
- Render: runs the Vapus API.
- GitHub Pages: serves the public website.
- Google Analytics and Google Fonts: on public website pages only. The signed-in vault does not use analytics.
Your part
- Use a strong, unique password and keep your email account secure.
- Send share links only to the person you mean, and revoke ones you no longer need.
- Give delegates the lowest access level that works, and remove access when it is no longer needed.
Found a security problem?
Please email contact@shoonyaorigins.com with the subject "Vapus security report". Describe what you found and how to reproduce it. Please do not access other people's data, and give us reasonable time to fix the issue before sharing it publicly.