Trust

Security, plainly stated

What Ventrax does to protect your data, what it does not do yet, and how to reach us if you find a problem.

What is in place

Tenant isolation

Your company's data is separated at the application layer and enforced again at the database, so a bug in one place is not enough to cross the boundary.

Encryption in transit

TLS on every connection. No exceptions for internal traffic.

Least privilege

Permissions are per-role and checked on the server for every action, not hidden in the interface.

Audit trail

Business actions record who, when and under what authority — kept as evidence, separate from technical logs.

Backups

Automated, tested by restoring rather than assumed to work.

What we do not claim

We hold no security certifications yet. Not ISO 27001, not SOC 2. Ventrax is designed with those frameworks in mind, but "designed with" and "certified" are different words and we will not blur them.

If your procurement process requires a certification we do not hold, tell us during evaluation rather than after. We would rather lose a deal honestly than win one we cannot support.

Reporting a vulnerability

Email security@ventraxerp.com. We will acknowledge within two working days. We will not pursue anyone who reports a genuine issue in good faith and gives us reasonable time to fix it.