Trust center
Security at Venuvero
A plain-language overview of the technical and organizational controls currently used to protect Venuvero workspaces and connected-provider data.
Effective September 8, 2026
Access and tenant isolation
Venuvero uses server-managed, HttpOnly, Secure session cookies. Session and reset tokens are stored as one-way hashes. Authenticated requests are bound to one organization, and workspace queries include that organization identifier. Administrative data export and deletion require the owner's current password.
Connected account protection
OAuth uses authorization code flow, one-time state, ten-minute expiration, and PKCE S256. Access and refresh tokens are encrypted at rest with AES-256-GCM and are never returned to the browser or included in an account export. Apple Calendar uses an Apple-generated app-specific password over HTTPS CalDAV; that credential receives the same encryption and export protections, and the primary Apple password is never requested. Venuvero asks for delegated, feature-specific access and fails closed if the provider does not grant it. Disconnecting immediately erases the encrypted credential and attempts Google-side revocation where available.
Application and network controls
Production traffic uses HTTPS. The API enforces an origin allowlist, cross-site mutation checks, request-size limits, validated request schemas, endpoint rate limits, redacted request logging, timeouts for outbound calls, and restrictive browser security headers. Public URL collection rejects credentials, private-network destinations, unsafe redirects, oversized responses, and disallowed robots instructions.
Payments, AI, and third parties
Stripe-hosted Checkout handles payment details, and Stripe webhook signatures are verified before billing state changes. AI requests use the minimum content needed for the selected feature and disable response storage where supported. Provider data is not used for ads or generalized AI training. Current service-provider categories and data uses are listed in the Privacy Policy.
Monitoring and response
Venuvero records security-relevant integration events without recording provider tokens. Suspected credential exposure is handled by revoking the affected secret or token, investigating scope, restoring from known-good code, and notifying affected users when required. Dependencies and production configuration are reviewed before releases.
Report a vulnerability
Please do not test against customer data, degrade availability, or access information that is not yours. Send a concise report with reproduction steps and impact through the contact channel below. Good-faith reports will be acknowledged and investigated.
Contact Venuvero through the support channel inside your account or email hello@venuvero.com.