Current controls
- Encrypted HTTPS connections for the public site and authenticated application traffic.
- Server-side session checks and role checks for protected account, admin, and diagnostic routes.
- Same-origin checks for protected state-changing requests and no-index rules for private surfaces.
- Secret storage outside the browser bundle, signed webhook checks, and restricted service credentials.
- Database access policies, scoped service access, audit records, and recovery-safe job claims.
- Suppression, reply-capture, identity, mailing-address, idempotency, and delivery-health gates for automated outreach.
- Dependency, type, build, and browser checks before a production release.
Limits
Security controls reduce risk but cannot remove it. Keep your password unique, protect access to your email account, sign out on shared devices, and report unexpected account activity promptly. VestBlock will never ask you to email a password, private key, or full payment-card number.
Responsible disclosure
If you believe you found a security issue, email acquisitions@vestblock.io with “Security report” in the subject line. Include the affected URL, a concise reproduction, and the impact. Do not access another person’s data, disrupt the service, use social engineering, or publish the issue before VestBlock has had a reasonable chance to investigate.
Incident response
VestBlock investigates credible reports, limits access when needed, preserves relevant records, fixes confirmed issues, and provides notices when applicable law requires them. Response time depends on severity and the information available to reproduce the issue.