Our approach
Security at IK Studios starts with collecting and storing less. The most effective protection for sensitive data is not to centralise it in the first place — which is why our products are built device-first wherever possible.
Protecting data
Data in transit is encrypted using current TLS. Secrets and tokens are handled as sensitive material, scoped to what they need, and kept out of user-facing exports. In Vault One, connected financial data is designed to stay on your device rather than in a central database.
Authentication & access
Account protection in Vault One supports email/password, Google and Apple sign-in, multi-factor authentication (authenticator app or email code), an account PIN, and biometric unlock on supported devices, with step-up verification for sensitive actions.
Internal access to production systems follows least privilege: limited to those who need it, protected by strong authentication, and intended to be auditable.
Infrastructure
We build on established providers rather than running our own data centres. Authentication and database services use Supabase; hosting uses Vercel and Railway; transactional email uses Resend; error monitoring uses Sentry where configured. Each is listed in the Subprocessor List.
Monitoring & logging
We keep security and audit logs to detect and investigate abuse, and use error monitoring to keep services reliable. Logs are retained for limited windows as described in the Data Retention Policy.
Vulnerability disclosure
We welcome good-faith security research. If you find an issue, please follow our Responsible Disclosure Policy. Machine-readable contact details are published per RFC 9116 — see the security.txt page.
What we do and don't claim
Honest posture
We do not currently hold SOC 2, ISO 27001, or similar third-party certifications, and we do not claim them. We describe what we actually do. If your organisation needs specific assurances or a security questionnaire completed, contact support@ikstudios.nl.
Product-specific security architecture for Vault One is documented in the Vault One Security & Infrastructure Policy.