Trust centre

Security

Security is part of how Vettro is designed: clear access, attributable actions and protection appropriate to sensitive contractor information.

Security by design

We design controls around least-privilege access, clear ownership and the separation of sensitive actions. Material changes and verification decisions are intended to remain attributable through permanent activity records.

Data protection

Information is protected in transit and at rest using industry-standard encryption where supported by the service. Access to production systems is restricted to authorised personnel with a legitimate operational need.

Application controls

  • Role-based access designed around organisational responsibilities.
  • Independent approval flows for sensitive information such as bank details.
  • Document version history and evidence-linked decisions.
  • Validation and controlled server-side access for protected operations.

Operational resilience

Our operating practices are designed to include monitored service health, controlled changes, dependency review, backups and recovery planning appropriate to the maturity and risk of the service.

Specific commitments, hosting locations and recovery objectives will be documented in customer agreements and security materials before production use.

Responsible disclosure

If you believe you have found a security issue, please do not access, alter or download data beyond what is necessary to demonstrate it. Send a concise report through our contact page and mark it as a security report.

Include the affected page, steps to reproduce and potential impact. We will acknowledge valid reports and coordinate remediation.