Security

Last reviewed: 9 May 2026

  • Read-only access to your Azure subscriptions — we never modify your infrastructure
  • Your data stays in the EU (Azure West Europe + North Europe regions)
  • EU-hosted infrastructure designed to support your GDPR obligations
  • Service-principal credentials encrypted at rest with AES-256
  • Per-tenant isolation enforced at the database layer (Postgres Row-Level Security)

Data access model

VNet IQ reads Azure resource metadata via a service principal you create in your tenant, granted the built-in Reader role on the subscriptions you choose. We never request write permissions, and we never modify your Azure infrastructure.

What we read

What we don't read

The Reader role is the smallest Azure built-in role that grants the listings we need. You can audit our access via Azure Activity Log — every ARM call we make is attributable to the service principal you provided. Revoking access is a single Azure portal click on that role assignment.

Where your data lives

Encryption

Authentication and tenant isolation

RLS materially reduces the risk of cross-tenant leakage by enforcing org scoping at the database layer, even if an application query omits a tenant filter or has a SQL bug. RLS is a defence-in-depth control, not a substitute for application-level review.

Subprocessors

We use three external services to operate VNet IQ. Each has signed Standard Contractual Clauses (SCCs) where applicable and processes customer data only as documented below.

Subprocessor Purpose Data processed Region
Microsoft Azure Application hosting, database, identity (Entra) All operational customer data EU (West Europe + North Europe)
Resend Transactional email delivery (welcome, trial reminders, near-quota warnings) Recipient email + display name + email body Email sending: EU (Ireland) when configured. Account metadata, logs, and API records may be processed in the US per Resend's region documentation.
Paddle Billing, payment processing, tax handling (Merchant of Record) Billing email + workspace name + transaction metadata EU + global (per Paddle's Merchant of Record model)

We do not currently use any other third-party processor for customer data. Infrastructure tooling (CI, DNS, registry) does not handle customer data and is not listed.

GDPR posture

Incident response

Contact

For all security and data-protection matters: [email protected].