Security & trust

One Suite, one set of protections — across every module.

Soft-Con Tracker, SkillVault, and MyVaultMate all run on the same platform, the same infrastructure, and the same controls below. Here's exactly how your data is handled.

Last updated: August 7, 2026

Encrypted in transit

All traffic is served over TLS with HTTP Strict Transport Security (one-year max-age, includeSubDomains, preload), automatic HTTPS redirection, secure-only session and CSRF cookies, and content-type-sniffing protection.

Sensitive fields encrypted at rest

Beyond database access controls, the most sensitive values we store — vendor bank/ACH details and software license keys — are individually encrypted at the application layer before they're written to disk. A database copy alone isn't enough to read them.

MyVaultMate: metadata only, by design

For every finding we store the PII type, severity, file location, the compliance frameworks it implicates, and at most a short redacted sample such as ***-**-1234 (capped at 64 characters). There is no field anywhere in the Suite that holds a raw PII value. Your files never leave your machines — the agent submits findings, not files.

Agent authentication

Each MyVaultMate device authenticates with an organization-scoped API token, sent as a bearer credential. Tokens are shown once at creation and stored only as a SHA-256 hash, are individually revocable, are rate-limited per token, and are never tied to a user's password. Revoke a token and that device stops in its tracks.

Account access

Passwords are hashed, never stored or visible in plaintext. Two-factor authentication (TOTP) is available on every account. Your organization's data is scoped to your organization — it never crosses into another customer's account.

Staff access is logged

Internal staff access is role-gated — a given staffer can only reach the sections their role covers — and sensitive actions, including any time staff view an account as you (impersonation) to help with support, are logged with who, when, and which account.

AI is staff-initiated, not self-service

You don't interact with AI directly. When our team generates a report or insight from your account data, it's initiated by staff and uses your existing data in the one module the report covers — never combined across modules, and never your payment, bank, or password data.

Payments via Stripe

All billing runs through Stripe. We never receive or store card data — only the amount, status, and a link to Stripe's hosted invoice.

Compliance & roadmap

We're a veteran-owned team building toward the formal attestations (like SOC 2) that regulated buyers expect. If your due-diligence process needs details on data residency, sub-processors, or our incident-response process, we'll walk you through where we stand today.