AuditVanguard
Back home
Security at AuditVanguard

Built for firms that carry
other companies' compliance.

Your clients trust you with their most sensitive evidence. Here is exactly how AuditVanguard protects it — no marketing gloss, just the controls as implemented.

Session & access protection

Sessions that can't be stolen by scripts.

httpOnly cookie sessions

Sign-in tokens live in Secure, httpOnly, SameSite cookies — never in localStorage — so malicious browser scripts (XSS) cannot read or exfiltrate them.

Automatic idle sign-out

Inactive sessions get a countdown warning, then are terminated server-side. Walking away from an open laptop doesn't leave client data exposed.

Multi-factor authentication

TOTP authenticator apps with single-use recovery codes, plus step-up verification for sensitive account changes.

Hardened credentials

Passwords are bcrypt-hashed with per-user salts. Reset links are single-use and expire in 60 minutes, with no account enumeration. Repeated failures lock the account.

Transport & browser hardening

Every response ships with strict security headers.

Secure headers on every request

HSTS forces encrypted connections, X-Frame-Options blocks clickjacking, and content-type sniffing, referrer leakage and cross-origin window access are all locked down.

Strict origin allowlist

The API only accepts credentialed requests from our own domains — no wildcard CORS, no third-party origins.

Tenant isolation by default

Every client workspace is enforced at the API layer with per-request ownership checks, and evidence files live in per-tenant storage paths.

No tokens in URLs

File downloads use short-lived, download-scoped tokens — the session credential never appears in links, logs or browser history.

Accountability

A record that stands up to scrutiny.

Hash-chained audit trail

Every material action is appended to a tamper-evident, hash-chained log that anyone can verify independently.

Version-locked exports

Every PDF snapshot is preserved as issued, so what an auditor saw can always be reproduced exactly.

Scoped auditor access

External reviewers work in a dedicated portal with read-only, engagement-scoped visibility — never inside your workspace.

Vendor risk

Subprocessors we rely on.

Stripe
Payments & subscriptions
Billing email, payment tokens
Resend
Transactional email
Names, email addresses
Twilio
SMS notifications
Phone numbers
OpenAI / Anthropic / Google
AI assistant & evidence mapping
Prompt content — never credentials
Emergent (hosting)
Compute, database, object storage
Application data, encrypted in transit

Vulnerability disclosure: /.well-known/security.txt

Questions about our security posture?

We'll walk you through any control on this page — or put it to work on your first engagement today.