1. Our Security Philosophy
At Venoy, security is built into the architecture. By heavily prioritizing client-side processing, we minimize the amount of data that ever touches our servers, drastically reducing the attack surface.
2. Secure Connections
All traffic to and from https://venoy.online is encrypted in transit using industry-standard Transport Layer Security (TLS/HTTPS). This ensures that any data moving between your browser and our infrastructure cannot be easily intercepted or tampered with.
3. Data Minimization & Client-Side Execution
The strongest security measure is not collecting data in the first place.
- Local Processing: Tools such as the PDF Toolkit, Image Toolkit, QR Studio, and Document Generators operate via client-side scripts. Your sensitive files (invoices, resumes, contracts) are processed locally in your device's memory.
- No Arbitrary Uploads: We do not upload your business documents to our servers for processing.
4. Infrastructure Security
For our web platform, API routes, and cloud utilities, we utilize modern, managed serverless infrastructure.
- Environment Isolation: Application code runs in isolated containerized environments.
- Dependency Management: We regularly audit and update our software dependencies (Node.js, React, Next.js, and third-party libraries) to patch known vulnerabilities.
- Environment Variables: API keys and sensitive configuration data are stored securely as encrypted environment variables and are never exposed to the client-side browser.
5. Data Hygiene & Zero-Retention
Our client-side architecture guarantees zero server retention for tool processing:
- Local files processed in PDF, Image, and Document tools stay in your browser memory and are destroyed upon closing or refreshing the tab.
- No permanent document stores or user-uploaded file databases are maintained.
6. Reporting a Vulnerability
We take security reports seriously. If you are a security researcher and believe you have found a vulnerability in Venoy, please contact us immediately.
We ask that you do not publicly disclose the vulnerability until we have had a reasonable timeframe to investigate and patch the issue.
Questions about this policy? Contact Venoy →
