Security

Trust must be designed in.

Security, privacy, and responsible data handling are foundational requirements across Vinova Lab products and customer solutions.

Our approach

A shared foundation, adapted to each risk.

Controls are selected according to the information processed, the deployment model, the integrations involved, and the operational risk of each use case.

This page describes Vinova Lab's corporate security principles. Individual products publish additional information appropriate to their data, users, and integrations.

Shared principles

Security across our products and platforms.

01

Identity and purpose

Access is authenticated, authorised, and limited according to the user, application, service, and purpose involved.

02

Data minimisation

Products are designed to process and retain only the information required by their purpose and customer configuration.

03

Lifecycle protection

Protection is considered during transmission, processing, storage, backup, retention, and deletion according to the applicable risk.

04

Environment isolation

Development, testing, and production use separate environments and credentials, with controlled service and data boundaries.

05

Traceability

Relevant processing and administrative operations are designed to be observable, reviewable, and attributable.

06

Human control

Sensitive or consequential automated actions can require human review and explicit approval.

Document and AI security

Customer knowledge remains under customer control.

Our platforms are designed to work with document knowledge without turning customer documents into an unrestricted, general-purpose training corpus.

  • Products can work with authorised on-premises and cloud storage locations.
  • Temporary processing copies are limited to what the selected workflow requires.
  • Retention and deletion depend on the product, deployment model, and customer configuration.
  • Access to document information preserves user and organisational context.
  • AI-generated answers and assessments are designed to remain connected to their supporting sources.
  • Personal or sensitive business information is not freely reused to train general-purpose models.

Where a product uses derived or anonymised information to improve specialised capabilities, the applicable conditions and product notice define how that information is prepared and used.

B2B and tailored solutions

Security shaped around the customer context.

B2B solutions may require controls beyond a standard product baseline. Requirements are assessed with the customer and reflected in the solution architecture, deployment configuration, integrations, and contractual documentation.

Depending on the engagement, this may include role and permission design, identity integration, retention and data-location requirements, approved external providers, audit information, recovery requirements, or customer-specific security assessment.

Available controls and commitments are confirmed for the individual solution rather than assumed to apply uniformly to every Vinova Lab product.

Privacy and data protection

Security supports responsible data processing.

Vinova Lab designs its products and customer solutions to support applicable data-protection requirements, including the EU General Data Protection Regulation where it applies.

Technical and organisational measures are selected according to the nature of the data, the processing purpose, the deployment model, and the associated risk. Information about personal data, legal bases, retention, rights, and international transfers belongs in the applicable privacy notice.

Read our Privacy Policy →
Product-specific security

Different products. Different risk profiles.

Each product documents the controls and considerations relevant to its users, data, integrations, and deployment model.

First product

rAInty Security

Product-specific information for rAInty, including controls related to consumer services and Open Banking integrations.

Read rAInty Security ↗
Continuous improvement

Security evolves with the platform.

Controls evolve with product maturity, customer requirements, operational experience, and the threat landscape. Certifications, independent assessments, and product-specific commitments are published only when formally achieved or contractually agreed.

Responsible disclosure

Report a potential vulnerability.

If you believe you have identified a security issue affecting Vinova Lab or one of our products, contact us confidentially at:

security@vinovalab.ai

What to include

  • The affected product, service, or domain.
  • A clear description and steps to reproduce the issue.
  • The potential impact and any relevant supporting material.

Responsible testing

Please do not access, modify, or delete information that does not belong to you; intentionally disrupt a service; or disclose an issue publicly before we have had an opportunity to investigate and coordinate remediation.