Security

You're about to hand us database credentials. Here's exactly what happens.

What we store01

We store

Table names, column names, data types, relationships, and your saved questions and dashboard definitions.

We never store

Your rows. Query results stream to your browser and are not persisted on our servers.

Connection credentials02

Credentials are encrypted at rest and decrypted only in memory to open a connection.

We use AES-256-GCM (authenticated encryption). The encryption key is derived from a server-side secret using scrypt (N=16384, r=8, p=1). Each credential blob includes a unique 12-byte IV and a 16-byte authentication tag, so tampering is detected, not just prevented.

Permissions we need03

Read-only. Nothing more. Here's the exact statement to create a restricted role, the thing founders care about more than anything else on this page.

-- PostgreSQL: create a restricted, read-only role for Vizkraft
CREATE ROLE vizkraft_ro WITH LOGIN PASSWORD '<generated-secret>';
GRANT CONNECT ON DATABASE your_db TO vizkraft_ro;
GRANT USAGE ON SCHEMA public TO vizkraft_ro;
GRANT SELECT ON ALL TABLES IN SCHEMA public TO vizkraft_ro;
-- keep new tables read-only too
ALTER DEFAULT PRIVILEGES IN SCHEMA public
  GRANT SELECT ON TABLES TO vizkraft_ro;
Compliance status04

We don't have SOC 2 yet. It's on the roadmap and we'll update here as soon as it's done. In the meantime, everything above (read-only access, AES-256-GCM encryption, no row storage) is how we earn your trust today.

Responsible disclosure05

Found a vulnerability? Report it to security@vizkraft.com. We don't pursue legal action against good-faith security researchers.