Trust
Security, plainly stated
What Ventrax does to protect your data, what it does not do yet, and how to reach us if you find a problem.
What is in place
Tenant isolation
Your company's data is separated at the application layer and enforced again at the database, so a bug in one place is not enough to cross the boundary.
Encryption in transit
TLS on every connection. No exceptions for internal traffic.
Least privilege
Permissions are per-role and checked on the server for every action, not hidden in the interface.
Audit trail
Business actions record who, when and under what authority — kept as evidence, separate from technical logs.
Backups
Automated, tested by restoring rather than assumed to work.
What we do not claim
We hold no security certifications yet. Not ISO 27001, not SOC 2. Ventrax is designed with those frameworks in mind, but "designed with" and "certified" are different words and we will not blur them.
If your procurement process requires a certification we do not hold, tell us during evaluation rather than after. We would rather lose a deal honestly than win one we cannot support.
Reporting a vulnerability
Email security@ventraxerp.com. We will acknowledge within two working days. We will not pursue anyone who reports a genuine issue in good faith and gives us reasonable time to fix it.