Security
Last updated: July 15, 2026
1. Security Overview
At VylioPass, security is our top priority. We implement industry-leading security measures to protect your data, prevent unauthorized access, and ensure the integrity of our Platform. This page outlines our security practices, certifications, and how you can help keep your account secure.
2. Infrastructure Security
2.1 Data Center Security
Our infrastructure is hosted in enterprise-grade data centers with the following security controls:
- Physical Security: 24/7 on-site security personnel, biometric access controls, CCTV surveillance, and mantrap entry systems
- Environmental Controls: Redundant power, cooling, and fire suppression systems
- Network Security: DDoS protection, intrusion detection/prevention systems (IDS/IPS), and network segmentation
- Certifications: ISO 27001, SOC 2 Type II, PCI DSS Level 1
2.2 Encryption
We encrypt data both in transit and at rest:
- In Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3 (Transport Layer Security)
- At Rest: All data stored in our databases and file systems is encrypted using AES-256 encryption
- Key Management: Encryption keys are managed using hardware security modules (HSMs) and rotated regularly
2.3 Network Architecture
Our network architecture follows security best practices:
- Zero Trust: We operate on a zero-trust model, requiring authentication and authorization for all internal and external access
- Segmentation: Production, staging, and development environments are fully isolated
- Firewalls: Web application firewalls (WAF) and network firewalls protect all entry points
- VPN: All internal access requires VPN with multi-factor authentication
3. Application Security
3.1 Secure Development Practices
Our development team follows secure coding practices:
- OWASP Top 10: We test for and mitigate all OWASP Top 10 vulnerabilities
- Code Reviews: All code undergoes peer review before deployment
- Automated Scanning: Static and dynamic application security testing (SAST/DAST) is integrated into our CI/CD pipeline
- Dependency Scanning: Third-party dependencies are scanned for known vulnerabilities
- Security Training: Developers receive regular security training
3.2 Authentication & Authorization
We implement robust authentication and access controls:
- Password Security: Passwords are hashed using bcrypt with salt and never stored in plain text
- Multi-Factor Authentication (MFA): MFA is available and recommended for all accounts, required for admin accounts
- Session Management: Sessions are secured with HTTP-only, secure cookies and expire after inactivity
- Role-Based Access Control (RBAC): Access to features and data is controlled based on user roles
- OAuth 2.0: Third-party integrations use OAuth 2.0 with scoped permissions
3.3 Payment Security
Payment processing is handled securely:
- PCI DSS Compliance: We are PCI DSS Level 1 compliant (the highest level)
- Tokenization: Credit card data is tokenized by Stripe and never stored on our servers
- 3D Secure: We support 3D Secure 2.0 for enhanced cardholder authentication
- Fraud Detection: AI-powered fraud detection analyzes transactions in real-time
4. Data Protection
4.1 Data Minimization
We collect only the data necessary to provide our services. We do not collect excessive or unnecessary personal information.
4.2 Data Isolation
Multi-tenant data is logically isolated using row-level security (RLS) in our database. Each organizer can only access their own data.
4.3 Backup & Recovery
We maintain comprehensive backup and disaster recovery capabilities:
- Daily Backups: Full database backups are performed daily
- Point-in-Time Recovery: We can restore to any point within the last 30 days
- Geographic Redundancy: Backups are stored in multiple geographic regions
- Disaster Recovery: Our RTO (Recovery Time Objective) is 4 hours, RPO (Recovery Point Objective) is 1 hour
4.4 Data Retention & Deletion
We retain data only as long as necessary and provide secure deletion capabilities. When you delete your account, your data is permanently removed within 30 days (except where retention is required by law).
5. Monitoring & Incident Response
5.1 Continuous Monitoring
We monitor our Platform 24/7 for security threats:
- SIEM: Security Information and Event Management system collects and analyzes logs from all systems
- Alerting: Automated alerts notify our security team of suspicious activity
- Penetration Testing: We conduct regular penetration testing by independent third parties
- Vulnerability Scanning: Continuous vulnerability scanning of all systems
5.2 Incident Response Plan
We maintain a comprehensive incident response plan:
- Detection: Automated systems and manual monitoring detect security incidents
- Containment: We isolate affected systems to prevent further damage
- Eradication: We identify and remove the root cause of the incident
- Recovery: We restore affected systems and data from clean backups
- Notification: We notify affected users and regulators as required by law (within 72 hours for GDPR)
- Post-Incident Review: We conduct thorough reviews to prevent recurrence
6. Compliance & Certifications
VylioPass maintains the following security certifications and compliance standards:
- PCI DSS Level 1: Payment Card Industry Data Security Standard (highest level)
- SOC 2 Type II: Service Organization Control 2 report covering security, availability, and confidentiality
- ISO 27001: International standard for information security management systems
- GDPR: General Data Protection Regulation compliance for EEA users
- UAE PDPL: UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data
We undergo annual audits by independent third-party auditors to maintain these certifications.
7. Your Security Responsibilities
While we implement robust security measures, you also play a role in keeping your account secure:
7.1 Account Security
- Strong Passwords: Use a unique, strong password (at least 12 characters with mixed case, numbers, and symbols)
- Multi-Factor Authentication: Enable MFA on your account for an extra layer of security
- Phishing Awareness: Be cautious of emails or messages asking for your password or personal information. VylioPass will never ask for your password via email
- Account Monitoring: Regularly review your account activity and report any suspicious activity
7.2 Device Security
- Secure Devices: Keep your devices secure with up-to-date operating systems and antivirus software
- Secure Networks: Avoid using public Wi-Fi for sensitive transactions
- Browser Security: Use up-to-date browsers and enable security features
7.3 Reporting Security Issues
If you discover a security vulnerability or suspect unauthorized access to your account, please report it immediately:
- Email: security@vyliopass.com
- Response Time: We will acknowledge receipt within 24 hours and provide an initial assessment within 72 hours
8. Bug Bounty Program
We operate a responsible disclosure program for security researchers. If you discover a security vulnerability in our Platform, we encourage you to report it to us. We may provide rewards for valid vulnerability reports at our discretion.
Scope: Our bug bounty program covers vulnerabilities in the VylioPass web application, APIs, and mobile apps.
Out of Scope: Denial-of-service attacks, social engineering, physical security testing, and third-party integrations.
Reporting: Submit reports to security@vyliopass.com with detailed reproduction steps.
9. Security Updates & Communication
We regularly update our Platform to address security vulnerabilities and improve security features. We communicate security updates through:
- Status Page: status.vyliopass.com
- Email Notifications: For critical security updates affecting your account
- Security Blog: Detailed posts about security improvements and best practices
10. Contact Our Security Team
For security-related inquiries or to report a vulnerability:
- Security Team: security@vyliopass.com
- PGP Key: For sensitive communications, use our PGP key (available upon request)
- Emergency: For urgent security incidents, call +971-XX-XXX-XXXX (24/7)
Related: Terms of Service · Privacy Policy · Cookie Policy · GDPR Compliance