Our trust principles
Trust is something we earn in how we build, not something we assert. Four principles guide every product decision at IK Studios:
Data minimisation
Collect the least we need to run a feature, and avoid building databases of sensitive data we do not need to hold.
Device-first
Where we can keep your data on your device instead of our servers, we do — this is core to how Vault One is designed.
Least privilege
Access to systems and data is scoped, authenticated, and logged. Connections to third parties are read-only where the product allows it.
Honest defaults
No dark patterns, no tracking-by-default, and no quiet selling of your data. The private choice is the default choice.
How our products protect data
Our products are built so that the most sensitive information stays close to you. Vault One, for example, connects to banks and financial providers read-only and is designed to keep connected balances, transactions, and net-worth figures on your device rather than in a central financial database.
When data must reach a server — for example your account email, subscription status, or security logs — it is encrypted in transit and handled by a small set of vetted providers listed in our Subprocessor List.
The complete, product-specific architecture for Vault One — including device-local storage, connectors, and export handling — is documented in the Vault One Trust Center.
Infrastructure & subprocessors
We run on established, security-focused infrastructure rather than managing our own data centres. The providers that may process limited data on our behalf are named in the Subprocessor List, with the role each one plays.
Representative providers include Supabase (authentication and database for Vault One), Stripe (subscription billing), Resend (transactional email), Vercel and Railway (hosting), and Sentry (optional error monitoring). Marketing and legal pages are served as static sites.
Verified against our build
The subprocessors and technologies named across this center reflect what is actually wired into our products and websites today — not aspirational integrations. See the Subprocessor List and Third-Party Services for the current map.
Authentication & access
Account security in Vault One supports email and password sign-in, Google and Apple sign-in, multi-factor authentication (authenticator app or email code), an account PIN, and biometric unlock on supported devices. Sensitive actions require step-up verification.
Internally, access to production systems is limited to the people who need it, protected by strong authentication, and intended to leave an audit trail.
Compliance posture
IK Studios is established in the Netherlands and operates under the EU General Data Protection Regulation (GDPR). Our GDPR Compliance page sets out lawful bases, data-subject rights, and how to exercise them.
What we do not claim
We do not currently hold formal third-party certifications such as SOC 2 or ISO 27001, and we do not claim them. We would rather state our posture honestly than imply audits we have not completed. If your organisation requires specific assurances, contact us and we will share what we can.
Reporting a concern
Found a security issue, or have a privacy concern? We want to hear about it. Security researchers can follow our Responsible Disclosure Policy; privacy requests are covered in the Privacy Policy and Data Deletion Policy.
For anything else, the fastest route is email to support@ikstudios.nl.