Trust & compliance

Security

Last reviewed: 20 June 2026

  • Read-only access to your AWS, Azure, and Google Cloud environments — we never modify your infrastructure
  • Your data stays in the EU (Azure West Europe + North Europe regions)
  • EU-hosted infrastructure designed to support your GDPR obligations
  • Connection credentials encrypted at rest with AES-256
  • Per-tenant isolation enforced at the database layer (Postgres Row-Level Security)

Data access model

VNet IQ reads network metadata from your clouds through read-only roles you create and grant. On Azure, a service principal with the built-in Reader role. On AWS, a read-only IAM role you deploy via our CloudFormation template. On Google Cloud, a read-only service account granted the Compute Network Viewer and Browser roles (or a custom role limited to listing networks and subnetworks). We request read-only permissions only, and we never modify your infrastructure.

What we read

What we don't read

We request the smallest read-only role each cloud offers for the listings we need. You can audit our access via each cloud's audit log — Azure Activity Log, AWS CloudTrail, or Google Cloud Audit Logs — and every read is attributable to the role you provided. Revoking access is a single change on your side.

Where your data lives

Encryption

Authentication and tenant isolation

RLS materially reduces the risk of cross-tenant leakage by enforcing org scoping at the database layer, even if an application query omits a tenant filter or has a SQL bug. RLS is a defence-in-depth control, not a substitute for application-level review.

Subprocessors

We use three external services to operate VNet IQ. Each has signed Standard Contractual Clauses (SCCs) where applicable and processes customer data only as documented below.

Subprocessor Purpose Data processed Region
Microsoft Azure Application hosting, database, identity (Entra) All operational customer data EU (West Europe + North Europe)
Resend Transactional email delivery (welcome, trial reminders, near-quota warnings) Recipient email + display name + email body Email sending: EU (Ireland) when configured. Account metadata, logs, and API records may be processed in the US per Resend's region documentation.
Paddle Billing, payment processing, tax handling (Merchant of Record) Billing email + workspace name + transaction metadata EU + global (per Paddle's Merchant of Record model)

We do not currently use any other third-party processor for customer data. Infrastructure tooling (CI, DNS, registry) does not handle customer data and is not listed.

GDPR posture

Incident response

Contact

For all security and data-protection matters: [email protected].