Security

Vaethat enhances architectural renders. Studios and architects trust it with work that is often not yet public, so protecting that work is part of the product. This page sets out the information security policy and the measures behind it.

Information Security Policy

Vaethat protects the confidentiality, integrity and availability of the images and data its customers entrust to it. This policy is approved by Vaethat's founder and director. It applies to everyone who works on Vaethat and to any supplier with access to its systems or customer data, and it is reviewed at least once a year.

  • Encryption: Data is encrypted in transit with TLS 1.2 or later and at rest with AES 256.
  • Storage in the EU: Accounts, projects and images are stored with Supabase on AWS in Stockholm, Sweden.
  • No training on your images: Customer images are never used to train Vaethat's model.
  • Ownership: Customers own their original images and the enhanced results.
  • Providers: Vaethat runs on cloud providers chosen for their security certifications: Supabase (SOC 2 Type 2, ISO/IEC 27001), AWS (ISO/IEC 27001, SOC 2) and Vercel (SOC 2 Type 2, ISO/IEC 27001). Payments go through Stripe (PCI DSS Level 1), and card details never reach Vaethat.
  • Backups: The database is backed up every day.
  • Changes: Every change is tested on a separate preview build before it is released.
  • Updates: Software is kept up to date, and the security of the configuration is reviewed regularly.
  • Deletion: Customers can delete their images at any time. Images are deleted within 30 days of closing an account.
  • Incidents: Security incidents are handled by the founder. Customers affected by a personal data breach are told as soon as it is found, and within 72 hours at the latest.
  • Personal data: Personal data is handled under the GDPR.

Report a Security Issue

If you believe you have found a security issue in Vaethat, write to support@vaethat.com with "Security" in the subject. Please include enough detail to reproduce it, and do not access or change other people's data.

More Information

The Privacy Policy explains how personal data is handled, and the Terms of Service set out the service and its limits.