Security

Effective date: August 12, 2026

This page describes public security and trust principles for the VINTOLK ecosystem. It is intended to help users and reviewers understand how VINTOLK approaches protection of accounts and product access.

This page does not disclose sensitive implementation details, internal topology, or confidential controls.

Transport security

VINTOLK public product websites and APIs are intended to be accessed over HTTPS so that browser and API traffic is encrypted in transit.

Authentication

VINTOLK products that require sign-in authenticate users through a VINTOLK Account.

Supported sign-in methods may include Sign in with Google and email/password authentication where enabled for the product.

Google Sign-In is used for identity authentication. VINTOLK does not receive Google account passwords through that flow.

Authorization separation

Authentication establishes who you are. Product authorization determines what you can do.

Organization roles, workspace membership, and product permissions remain the authority for product actions. Being signed in does not by itself grant Organization or workspace authority.

Product session separation

Independent VINTOLK products may share the same VINTOLK Account identity while maintaining separate product sessions and application data boundaries.

Product sessions are designed to remain scoped to the product origin rather than broadly shared across the entire ecosystem domain.

Controlled infrastructure access

Production infrastructure access is limited to authorized operators and controlled operational processes.

VINTOLK uses managed cloud and platform services to host and operate product components. Exact internal topology is intentionally not published on this page.

User security practices

Users can help protect their accounts by:

  • Using strong, unique passwords for email/password sign-in
  • Keeping Google account security settings current when using Google Sign-In
  • Signing out on shared devices
  • Reporting suspicious account activity promptly

Security reporting

If you believe you have found a security issue in a VINTOLK product or website, please report it responsibly by emailing support@vintolk.com with enough detail for us to investigate.

Please do not publicly disclose vulnerability details before we have had a reasonable opportunity to investigate and respond.

Test Lab

Test Lab is a direct VINTOLK path for developers and engineering teams who need deeper software testing and stronger assurance before important changes reach production.

The Test Lab page on this website is the official customer explanation. The product continues at test.vintolk.com.

What this page does not claim

Unless separately published with supporting evidence, this page does not claim specific third-party certifications such as SOC 2 or ISO 27001, and does not assert completion of a formal external penetration-test certification.

Contact

For security reports, email support@vintolk.com. For privacy or general help, see the Help page. For commercial questions, see For Business.

Back to homepage