Security

Security you can verify

Effective: [EFFECTIVE_DATE]

Draft — review with legal counsel before launch. This document uses placeholder values (in brackets) and standard template language. Replace all placeholders and have counsel review before relying on it.

Encryption in transit & at rest

We encrypt data in transit using TLS, and we encrypt data at rest in our hosting and database layers. Many remittance files are parsed directly in your browser, so their contents never touch our servers. When data does reach us, it is protected by encryption end to end.

Access controls & least privilege

Access to production systems is restricted to the people who need it, granted under the principle of least privilege, and reviewed regularly. Administrative access requires strong authentication, and we log activity so we can audit who did what. We remove access promptly when it is no longer needed.

HIPAA & BAA

When you use Visera to process protected health information, we act as a Business Associate under HIPAA and handle that data only to provide the service. We maintain administrative, physical, and technical safeguards appropriate to the data we process. A Business Associate Agreement (BAA) is available on request.

Infrastructure & subprocessors

We run on reputable cloud infrastructure and a small set of vetted subprocessors, each bound by contract to protect your data. Our core providers include Supabase for authentication and database hosting, Stripe for payments, Resend for email, and Sentry and PostHog for monitoring and analytics. We review these vendors and limit what we share to what each one needs.

Data retention & deletion

We retain only what we need, for only as long as we need it. Parsed file data is kept for the minimum period required to deliver the feature you used, and account data is removed or de-identified after you close your account, except where the law requires us to keep it. You can request deletion at any time.

Vulnerability reporting

We welcome reports from security researchers. If you believe you have found a vulnerability, please email security@viseraapp.com with the details and steps to reproduce. Give us a reasonable window to investigate and fix the issue before disclosing it publicly, and we will work with you in good faith.