Your collection data, locked down

Security isn't an afterthought. Every layer of Vaultry is built to keep your data private and protected.

Encryption

All data is encrypted at rest using AES-256 and in transit using TLS. Your collection details are never stored in plaintext.

Infrastructure

Hosted on AWS with server-side encryption on S3 for all stored files. Infrastructure is monitored and kept up to date.

Backups

Automated daily backups plus on-demand full ZIP exports — data, photos, and custom-field values all included. Multi-gigabyte downloads stream directly through S3 with a live progress bar.

HMAC-Signed Backups

Every backup manifest is cryptographically signed with HMAC-SHA256 over the canonical JSON body. Unsigned (legacy v1) and tampered manifests are rejected on restore with a forensic activity-log entry. A versioned keystore means backups taken during a key rotation still verify.

Tenant-Locked Restores

Every backup manifest carries the originating tenant ID. A backup from account A cannot be restored into account B — cross-account restores are rejected with reason "mismatch" and logged to the activity stream. Stolen or leaked backup files cannot be opened in someone else's vault.

Authentication

Sign in with Google OAuth or secure email sessions. No plaintext passwords are ever stored. Sessions are encrypted and short-lived.

Data Ownership

Your data belongs to you. We never sell or share it. Full export is always available. Request account deletion and we permanently remove all data - inventory, photos, backups, everything.

Database-Level Tenant Isolation

Multi-tenant isolation is enforced by PostgreSQL Row-Level Security policies, not by application code. Every query, on every table, every time. Even if a bug bypasses an application check, the database refuses to return another tenant's rows.

Forensic Activity Log

Every action — create, update, delete, login, restore, override, account deletion — is recorded with IP address, user-agent, request ID, HTTP method, path, and status code. 180-day retention with one-click CSV or JSON export. Exactly the audit trail you want when an insurer, executor, or attorney asks.

Protected Fields with Audited Override

Serial numbers, VINs, cert numbers, reference numbers, and assay numbers are locked the moment they're set. Corrections require a written justification, captured in the activity log with a from → to delta. No silent edits to the identifiers that legally matter.

No AI Processing

We never process your data with AI or machine learning. Your inventory details, photos, and personal information are never used for training or inference.

What we don't do

We don't sell your data. We don't share it with third parties. We don't use your collection information to serve ads or build marketing profiles.

We don't track your usage for advertising purposes. The only analytics we use are basic, privacy-respecting metrics to keep the product running smoothly.

Your inventory is your business. We built Vaultry to be a tool you can trust with sensitive information, and we take that responsibility seriously.

Curious how we handle uptime and incidents? See our Service Level Commitment for our availability target and incident-response practices.

Ready to secure your collection?

30-day free trial — cancel anytime. Your data is protected from day one.