All traffic uses TLS 1.2 or higher, stored application data is encrypted at rest, and row-level security policies isolate each account. Passwords are checked against known breach databases, Google Sign-In is available, anonymous logins are disabled, and public endpoints use rate limiting, input validation, and SSRF protection.
VPP does not sell customer data. After cancellation, business data is retained for 30 days with available CSV and PDF exports.