Security

We hold the keys. Here is how we hold them.

A credential governance tool is only worth using if it is the most careful system in your stack. This page is what we would want to read before trusting someone with ours.

Last reviewed · 2026-08
Contact · security@vyoogam.com
Data handling

What we store

For most vendors we store the credential encrypted so we can check its cost and quota. For HashiCorp Vault and GCP Secret Manager, you give us a reference instead of the value — we fetch it at request time and never store it (Enterprise).

Encryption

Encrypted at rest, tenant-scoped key

Credentials are encrypted at rest. You can supply your own key (BYOK) on any plan; Enterprise adds the ability to rotate it.

Access

Role-scoped, logged

RBAC scopes who on your team can see or manage what. Staff access to the operator console is logged.

Controls

Current posture.

ComplianceFormal certifications (SOC 2, ISO 27001) are on our roadmap as we scale
PlatformRole-based access controlAudit log of every action taken in SubScopeSlack alerts on new findingsVault / GCP Secret Manager credential sourcing — no raw value required (Enterprise)
Disclosuresecurity@vyoogam.com · PGP key on requestAcknowledgement within 2 business daysSafe harbour for good-faith researchPublic bug bounty · planned
Incident

If something goes wrong.

Affected customers are notified within 24 hours of confirmation, with what was accessed, when, and what we did. We publish a post-mortem on the blog for any incident that affects more than one customer. We have not had one. We are writing this page as if we will.

Recommendation

Shrink your blast radius this week.

Connect one vendor. SubScope will show you what you have been trusting. Free during public beta.

Sign in Talk to us