Data Security & Compliance Overview
Vendi Today is built on infrastructure that's independently audited and certified to widely recognized security standards, so you can store customer data, run communications, and process payments with confidence.
Certifications and standards
- SOC 2 Type II — an independent audit confirming that security, confidentiality, and availability controls aren't just documented but have been proven effective over an extended period of real-world operation (a higher bar than a one-time assessment).
- ISO/IEC 27001:2022 — the international standard for information security management systems.
- GDPR and CCPA readiness — practices aligned with major data privacy regulations.
- CAN-SPAM readiness — support for compliant email marketing practices.
- Annual third-party penetration testing.
None of this requires any setup on your part — it describes how the platform itself is operated and audited.
How your data is protected
- Encryption in transit — all data moving to and from Vendi Today uses TLS 1.2/1.3 with 2,048-bit (or better) keys.
- Encryption at rest — stored data is encrypted using AES-256.
- Password protection — passwords are hashed and encrypted, never stored in plain text, and must meet minimum complexity requirements.
- Multi-tenant isolation — every account's data is logically separated using unique identifiers, so one business's records are never mixed with another's.
Features you can use
- Two-factor authentication (2FA) — turn this on for your login under your account security settings for an extra layer of protection.
- Role-based access — control which team members can see or edit which records.
- Recycle bin recovery — accidentally deleted contacts and opportunities can be restored for up to 30 days.
- Backups — seven days of retained backups with point-in-time recovery in case something needs to be rolled back.
- Data export — you can export your own data at any time through the built-in export tools.
Bottom line
You don't need to configure anything to benefit from the certifications and encryption standards above — they're built into the platform. Where you do have a role is in your own account hygiene: enable 2FA, set sensible team permissions, and know that the recycle bin and export tools are there if you ever need them.
Was this article helpful?
