Trust & security

Security at Vantix.

Last updated: July 23, 2026

One customer per machine

The strongest isolation is physical. Every lease is one dedicated Apple M4 Mac mini — never shared, never virtualized, no hypervisor between you and the hardware. Each machine sits on its own private VLAN, walled off from every other customer at the network switch. Your traffic, your logins, and your workloads are never on hardware or network segments that anyone else can touch.

The rack

Our fleet runs in an operator-controlled facility with UPS-backed power for the network core, automatic restart after power events, and dedicated symmetric business fiber from a tier-1 ISP. The rack is monitored continuously — the same live measurements we publish on our status page are the ones we watch ourselves. The people with physical access to the hardware are the same two operators who answer support.

Accounts & access

Authentication is handled by Supabase Auth: passwords are stored hashed, never in plaintext, and OAuth sign-in (Google, Discord) uses the PKCE flow. Two-factor authentication is available on every account, and administrative access to fleet controls is verified server-side on every request. Machine credentials are delivered through your dashboard over HTTPS, with a temporary password you're required to change on first login.

Payments

All payments run through Stripe's hosted checkout. Card numbers never touch our servers — Stripe is a certified PCI DSS Level 1 service provider, the highest level of payment-security certification. Billing webhooks from Stripe are cryptographically signed and verified before we act on them; an unsigned or tampered event is rejected outright.

Your machine, your data

We do not access the contents of your leased machine except with your explicit permission for support, or where strictly required to protect the network. When a lease ends, the machine is securely wiped before it is ever re-provisioned. We recommend keeping your own backups — by design, we do not copy or retain your data.

Data protection & GDPR

We collect the minimum we need to run the service: your email, hashed credentials, and machine assignment. We don't sell or share personal data, and we don't run cross-site tracking. Wherever you are — including the EU — you can request a copy or deletion of your data at any time by emailing vantixservers@gmail.com; deletion completes within 30 days, except records we're legally required to keep. Full details in our Privacy Policy.

Compliance & roadmap

Payment processing is PCI DSS compliant through Stripe. Our internal controls — access management, isolation, monitoring, change control — are built in line with the SOC 2 Trust Services Criteria, and a formal SOC 2 audit is on our roadmap as the fleet scales. One clear boundary: Vantix machines are not intended for regulated health data — we do not sign Business Associate Agreements, so HIPAA-covered workloads should not be run on the service.

Responsible disclosure

Found a vulnerability? Email vantixservers@gmail.com with "Security" in the subject line. We read every report, respond quickly, and will never pursue good-faith security research. If you can, include steps to reproduce — it gets fixes shipped faster.