Security Statement

Last Updated: August 7, 2026

Our Commitment

At Vidata, protecting customer data is fundamental to how we design, build, and operate our platform. We understand that our customers trust us with sensitive financial and business information. Security is incorporated into our architecture, development practices, and operational processes to help protect that information throughout its lifecycle. This Security Statement provides an overview of the safeguards and practices we use to protect customer information.

1. Security Philosophy

Vidata is designed around a simple principle: Your business data belongs to you.

Our responsibility is to securely process that information so you can gain meaningful insights into your business while maintaining confidentiality, integrity, and availability.

Security is considered throughout the software development lifecycle, including application design, infrastructure planning, authentication, data processing, deployment, and ongoing maintenance.

Rather than relying on a single security control, Vidata follows a defense-in-depth approach where multiple layers of protection work together to reduce risk.

2. Security Principles

Our security program is guided by several core principles.

Principle Description
Least Privilege Access to systems and customer information is limited to what is necessary to perform authorized functions.
Secure by Design Security considerations are incorporated into product architecture and development rather than added later.
Defense in Depth Multiple layers of technical and operational safeguards work together to reduce risk.
Customer Control Customers control which third-party services they connect and may disconnect those integrations at any time.
Continuous Improvement Security practices are reviewed and enhanced as our platform and customer needs evolve.
Data Ownership

Vidata does not claim ownership of customer data. Our systems process customer information only for the purpose of providing the services requested by our customers.

3. Infrastructure Security

Vidata is hosted using reputable cloud infrastructure providers selected for their reliability, security capabilities, and operational maturity.

Our infrastructure is designed to support secure application hosting, data processing, and business continuity while helping protect customer information from unauthorized access.

Infrastructure Practices

Infrastructure configurations are periodically reviewed and updated to address evolving security requirements and operational needs.

4. Encryption

Vidata is designed to protect customer information while it is transmitted, processed, and stored. Where appropriate, encryption technologies are used to help safeguard sensitive information from unauthorized access.

4.1 Data in Transit

Communication between customers and the Vidata platform is protected using HTTPS with Transport Layer Security (TLS). This helps protect information transmitted between your browser, connected services, and the Vidata platform from interception or tampering during transmission.

4.2 Data at Rest

Customer information stored by Vidata is protected using the security capabilities provided by our hosting infrastructure and database platforms. Where supported, sensitive information is stored using encryption or other appropriate safeguards designed to reduce the risk of unauthorized access.

4.3 Credential Protection

Vidata does not store customer passwords in plain text. Authentication credentials are handled using secure authentication mechanisms and industry-accepted password hashing practices.

Important

Vidata never requests or stores your QuickBooks username or password. Authentication is performed directly by Intuit using OAuth 2.0.

5. Authentication & Authorization

Authentication and authorization controls help ensure that only authorized users can access customer information.

Identity Verification

Authorization

Access to customer information is controlled based on the authenticated user and the permissions associated with that account. Users can access only the information that they are authorized to view within the Service.

Administrative Access

Administrative access to production systems is limited to authorized personnel who require such access to operate, maintain, or support the Service. Administrative activities may be logged to support operational oversight and security investigations.

6. QuickBooks OAuth Security

Vidata integrates with QuickBooks Online using Intuit's OAuth 2.0 authorization framework. This approach allows customers to securely authorize Vidata without sharing their QuickBooks credentials.

How OAuth Works

  1. The customer chooses to connect QuickBooks Online.
  2. The customer is redirected to Intuit's secure authentication page.
  3. The customer signs in directly with Intuit.
  4. The customer reviews and approves the requested permissions.
  5. Intuit issues secure authorization tokens to Vidata.
  6. Vidata uses those tokens only to access authorized QuickBooks data.

Customer Control

Customers remain in control of their QuickBooks connection. You may revoke Vidata's authorization at any time by:

Once access is revoked, Vidata can no longer retrieve new information from your QuickBooks organization.

Permission Scope

Vidata requests only the permissions reasonably necessary to provide the features supported by the Service. We do not request unnecessary access to customer information.

7. AI & Data Processing

Vidata uses Artificial Intelligence to help customers analyze business information and generate insights based on the data they choose to connect or upload.

AI Processing Principles

Data Minimization

Vidata is designed to use only the information reasonably necessary to fulfill a customer's request. Where practical, processing is limited to the data relevant to the question or analysis being performed.

Model Training

Customer Data

Vidata does not intentionally use customer business data to train its own proprietary AI models without the customer's permission.

Where third-party AI providers are used to process customer requests, Vidata selects providers that offer enterprise security controls and appropriate data protection commitments.

8. Operational Security

Security is an ongoing operational responsibility. Vidata incorporates security considerations into software development, infrastructure management, system maintenance, and customer support processes.

Secure Development

We strive to build security into our software development lifecycle by following secure engineering practices throughout the design, implementation, testing, and deployment of new features.

Access Management

Access to production environments and customer information is limited to authorized personnel who require such access to perform their job responsibilities.

Administrative privileges are granted according to the principle of least privilege and are reviewed periodically as operational needs evolve.

Monitoring and Logging

Vidata maintains operational logs and monitoring capabilities to help identify service issues, investigate operational events, and support security investigations where appropriate.

Monitoring helps us identify abnormal application behavior, performance issues, and potential security events so that corrective actions can be taken when necessary.

9. Security Incident Response

Although no technology platform can eliminate all risk, Vidata maintains processes intended to detect, investigate, and respond to suspected security incidents.

Our Response Process

When a potential security incident is identified, Vidata seeks to:

  1. Identify and assess the nature of the incident.
  2. Contain the issue to reduce potential impact.
  3. Investigate the root cause.
  4. Implement corrective actions where appropriate.
  5. Restore affected services.
  6. Review lessons learned to improve future security.

Customer Notification

If Vidata determines that a security incident has materially affected customer information, we will provide notification as required by applicable law and based on the circumstances of the incident.

Where appropriate, notifications may include:

Continuous Improvement

Every significant security event is treated as an opportunity to improve our technology, operational processes, and customer protections.

10. Business Continuity

Vidata is designed with service continuity in mind. We maintain practices intended to reduce the impact of unexpected service interruptions and to support the recovery of customer services where practical.

Despite these measures, customers are encouraged to maintain copies of their own important business records and should not rely solely on any single online service for critical business continuity.

11. Third-Party Services

Vidata relies on selected third-party providers to deliver portions of the Service, including cloud infrastructure, payment processing, communication services, and Artificial Intelligence capabilities.

When selecting service providers, we consider factors such as security, reliability, operational maturity, and the ability to support our customers.

Service Category Purpose
Cloud Infrastructure Application hosting and secure data storage.
AI Services Natural language processing and business insights.
Email Services Account verification and customer communications.
Payment Providers Subscription billing and payment processing.

While we carefully select our service providers, each provider operates its own infrastructure and security program. Their services remain subject to their respective terms, privacy policies, and security commitments.

12. Customer Responsibilities

Security is a shared responsibility. While Vidata is responsible for protecting the platform and implementing appropriate security controls, customers also play an important role in safeguarding their own accounts and business information.

Customers are encouraged to:

Working together helps reduce security risks and contributes to a safer experience for all customers.

13. Responsible Disclosure

Vidata appreciates the efforts of security researchers and members of the security community who help identify potential vulnerabilities.

If you believe you have discovered a security vulnerability affecting the Vidata platform, we encourage you to report it responsibly so that it can be investigated and addressed.

When reporting a potential security issue, please include:

Good Faith Reporting

We ask that security research be conducted responsibly and in a manner that avoids disruption to customers, unauthorized access to data, or damage to our systems. Please do not access customer information, perform denial-of-service testing, or exploit vulnerabilities beyond what is reasonably necessary to demonstrate the issue.

14. Continuous Improvement

Security is an ongoing process rather than a one-time achievement. As Vidata grows, we continuously evaluate our architecture, development practices, infrastructure, and operational procedures to improve the security, reliability, and resilience of our platform.

We also periodically review this Security Statement to ensure it reflects our current practices and the evolution of our services.

15. Contact

If you have questions regarding this Security Statement or wish to report a security concern, please contact us.

Company Vidata
General Email hello@vidata.ai
Security Inquiries hello@vidata.ai
Website https://vidata.ai
Our Commitment to Security

Protecting customer trust is one of Vidata's highest priorities. We are committed to continuously strengthening our security practices, improving our platform, and being transparent about how we protect the information entrusted to us. Security is fundamental to our mission of helping businesses confidently understand and use their data.