Security
Last updated
1. Our Security Posture
VenturOS is built for solo builders, micro-SaaS operators and vibe coders building real businesses who want leverage without giving up control of their work. Security is not a feature we bolted on - it's the foundation we ship on.
2. Repository Access
Read-only by default. When you connect a GitHub repository, VenturOS requests scoped, read-only access. We do not write to your repo, push commits, open pull requests, comment on issues, or modify any files.
- OAuth scopes are limited to repo read access. We never request write or admin permissions.
- You can revoke access at any time from your GitHub settings or from inside VenturOS.
- Disconnecting purges your repository context from our systems within 24 hours.
3. AI & Your Data
Your code and business data are never used to train AI models.
- We contractually prohibit our AI providers from training on your data.
- Your inputs and the resulting outputs are processed only to fulfill your specific requests.
- You retain full ownership of your inputs and the AI-generated outputs.
- We tell you when you are working with AI and label AI-generated content, aligned with the EU AI Act's transparency requirements.
- Every sub-processor that touches your data is named in our Privacy Policy.
4. Hosting & Data Safeguards
Your data is hosted on Microsoft Azure with access controls and best-practice security safeguards. Encryption is being rolled out. API keys, OAuth tokens, and service credentials are stored in a managed secret store, never in plain text and never in source code.
5. Authentication & Access Control
- Account authentication is handled by a managed identity provider with industry-standard hashing for any password material.
- Session tokens are scoped, rotated, and short-lived.
- Internal employee access to production data is limited to need-to-know, audited, and granted on a temporary basis only when required for support.
6. Sub-Processors
VenturOS relies on a small set of vetted, individually named sub-processors. The authoritative list, with the data each one processes, is in our Privacy Policy:
| Sub-processor | Purpose | Region |
|---|---|---|
| Microsoft Azure | Hosting, compute, object storage | EU / US |
| Supabase, Inc. | Database, auth, edge functions | EU |
| Cloudflare, Inc. | CDN, DNS, edge delivery, cookieless analytics | Global |
| Brevo (Sendinblue SAS) | Transactional and product email | EU |
| GitHub, Inc. | Read-only repository context | US |
| Anthropic, OpenAI, Google | AI inference for AI-powered features | US |
| OpenRouter, Inc. | AI model routing and inference gateway | US |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | US / EU |
| Stripe, Inc. | Payment and subscription processing | US / EU |
All sub-processors are bound by data processing agreements that require them to maintain appropriate security measures and process your data only on our instructions.
7. Data Residency
Customer data is stored primarily in the EU and the US, depending on the sub-processor. We are evaluating regional residency options for enterprise customers. If you have specific residency requirements, contact hello [at] ventur-os.com.
8. Vulnerability Reporting
We welcome responsible disclosure. If you believe you have found a security issue in VenturOS, please email hello [at] ventur-os.com with details and reproduction steps. We commit to responding within 72 hours.
Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate.
Scope: ventur-os.com, app.ventur-os.com, and our public API endpoints. Out of scope: denial-of-service testing, social engineering of our staff or vendors, physical attacks, spam or rate-limit abuse, automated scanner output with no demonstrated impact, and issues in third-party services we do not operate.
Safe harbour: if you make a good-faith effort to follow this policy, avoid privacy violations and service degradation, only interact with accounts you own or have explicit permission to test, and give us reasonable time to remediate before disclosure, we will not pursue or support legal action against you for your research.
Our machine-readable policy lives at /.well-known/security.txt (RFC 9116).
8b. Acknowledgments
We credit researchers who report valid issues to us, with their permission. No reports have been published yet; this section is where we will list them.
8a. Incident and Breach Notification
If a personal data breach is likely to result in a risk to your rights, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours, and the UAE Data Office where the PDPL applies. Where the risk to you is high, we notify you directly without undue delay. Full detail is in section 16 of our Privacy Policy.
9. Compliance Roadmap
VenturOS is in early access. We are actively building toward formal certifications:
- SOC 2 Type II - engagement planned for 2026.
- GDPR alignment - see our Privacy Policy for current commitments.
- ISO 27001 - under evaluation for 2027.
10. Contact
Security questions, sub-processor lists for procurement, or DPA requests: hello [at] ventur-os.com.