Back to home
Template notice — this is a starting-point template and has not been reviewed by legal counsel. Replace before commercial launch.

Security

Security is foundational to how Virtual Buddy is built. This overview describes the technical and organizational measures we use to protect your data. It is a summary intended for prospective and current customers, not an exhaustive specification.

Encryption in transit

All traffic between your browser and the Service is encrypted using TLS. Data exchanged with our infrastructure providers and third-party APIs is likewise transmitted over encrypted connections.

Encryption at rest

Data stored in our managed database and hosting infrastructure is encrypted at rest by our infrastructure providers using industry-standard algorithms.

Token & credential encryption

Sensitive credentials, including the OAuth access and refresh tokens issued when you connect a third-party platform, are encrypted at the application layer before being stored. Tokens are decrypted only in memory, only when needed to perform an action you have authorized, and are deleted when you disconnect a platform or delete your account.

Tenant isolation

The Service is multi-tenant. Every request is scoped to the authenticated account, and data access is enforced by account (tenant) identifiers at the application and data layers so that one customer’s data is not exposed to another. Authentication and session management are handled by a dedicated identity provider.

Access control

Access to production systems is limited to authorized personnel on a least-privilege basis and protected by strong authentication. We log administrative access and review permissions periodically.

Data minimization & AI processing

We transmit only the data necessary to fulfil a given request to our AI model provider, and we do not permit API data to be used to train foundation models. See our Privacy Policy and Sub-processors page for details.

Responsible disclosure

We welcome reports from security researchers. If you believe you have found a vulnerability, please report it to security@virtualbuddy.app with enough detail to reproduce the issue. Please give us a reasonable opportunity to investigate and remediate before public disclosure, and avoid accessing or modifying data that is not yours. We will acknowledge valid reports and keep you informed of our progress.

Contact

For security questions or to request more information about our practices, contact security@virtualbuddy.app.

Last updated: 9 July 2026