Security

Last updated 18 August 2026

This page describes how VineFile is built and operated. It is our own statement about our own product — it is not an audit, a certification, or an assessment by anyone else. Bracketed items still need confirming.

Workspace isolation

Every record belongs to exactly one workspace. Access rules are enforced in the database itself, not just in the application, so a request for data outside your workspace fails at the storage layer regardless of what the client asks for.

Cross-workspace features work the same way. Lead buyers see a masked preview until they claim a lead. Marketplace listings stay anonymous until an offer is accepted. Seller notes on a listing are readable only by the seller.

Access control

Members hold one of three roles — owner, member or partner — and partners see only the referrals shared with them. Privileged operations run through checked database functions rather than direct table access, so a caller cannot escalate by crafting a request.

Encryption

Traffic to and from VineFile is encrypted in transit with TLS. Data at rest is encrypted by our hosting provider. We do not offer end-to-end encryption, and we say so rather than implying otherwise: our servers can read your records in order to run search, alerts and AI features.

Documents

Files uploaded to a client record are stored in private buckets and served through short-lived signed links. They are not publicly addressable.

Consent and contact records

Consent evidence and the compliance audit trail are append-only. Entries cannot be edited or deleted through the application, because their value depends on not being rewritable after the fact.

Sub-processors

We rely on third parties for hosting, database, email delivery, payment processing and AI inference. A current list is available on request at support@vinefile.com.

Reporting a vulnerability

Send anything you find to support@vinefile.com. Include enough detail to reproduce it. We will acknowledge within five business days.

Please do not run automated scans against production, access accounts that are not yours, or exfiltrate data — report the finding instead. We will not pursue anyone who reports in good faith and follows that.

Incidents

If a breach affects your data we will notify you at the address on your account, within the timeframe the applicable law requires, with what we know and what we are doing about it.