Every piece of data processed on vita platforms is protected under international security standards. Our customers' trust is the foundation of every service we provide.
Our certifications, issued by independent audit bodies, are concrete proof of our security commitment.
ISO/IEC 27001 is the globally recognized international standard for information security management systems. This certification documents that personal data, operational data and infrastructure components are systematically protected, risk management processes are applied, and vulnerabilities are continuously audited.
ISO 9001 is the international quality management standard that ensures product and service quality through systematic processes. All of vita's software development, testing and support processes are managed to this standard, delivering a consistent and reliable service experience to our customers.
At vita platforms, security is not a feature added afterward — it's an approach designed into the architecture from the very start. Security controls applied at every layer protect your data.
All data communication is end-to-end encrypted with the TLS 1.3 protocol. Every connection between server and client is protected with strong encryption algorithms. Sensitive data is stored with AES-256.
With multi-factor authentication (MFA), role-based access control (RBAC) and session management, only authorized users can access relevant data. Access logs are kept on record.
Our systems, hosted in ISO 27001-certified data centres, are continuously monitored with firewalls, intrusion detection/prevention systems (IDS/IPS) and regular security scans.
Your data is automatically backed up daily and stored in geographically separate locations. In the event of an outage, business continuity plans kick in to ensure minimum downtime.
All critical operations in the system are tracked with timestamped, immutable audit log records. Abnormal behaviour is reported to the security team via real-time alert systems.
Full compliance with personal data protection law and GDPR requirements is ensured. Data processing purposes are transparently defined; data subject rights are fully protected.
At vita, we manage security proactively rather than reactively. Security controls are applied at every stage of the software development process; we continuously verify our security posture through periodic penetration tests and independent audits.
Every new feature and system component is designed with threat modelling and security requirements in mind. Vulnerabilities are caught early in the development process.
Static and dynamic code analysis tools run a security scan on every release. Third-party dependencies are continuously monitored for vulnerabilities.
Annual penetration tests carried out by independent security firms measure our systems' resilience against real-world attacks, and any gaps are addressed.
All employees go through regular security awareness training. Readiness tests against social engineering attacks are conducted.
Documented response procedures and communication plans are in place for potential security breaches. A 24/7 security monitoring team is on duty.
Yes, our systems undergo penetration testing by independent security firms at least once a year. In addition, static and dynamic code analysis is applied on every software release, and any vulnerabilities found are fixed as soon as possible based on priority.
When a customer stops using the system, upon request all personal data is deleted, destroyed or anonymized in line with data protection law and data controller registry obligations. Written confirmation is provided once deletion is complete.
If a security breach affecting personal data is detected, the relevant data protection authority is notified within 72 hours as required by law. Affected customers are informed as soon as possible after the incident is identified. The scope of the breach, measures taken and recommended steps are shared transparently.
Access to customer data is restricted to cases of technical support and operational necessity, following the principle of least privilege. All access is logged and audited. Employees sign confidentiality agreements and undergo regular security training.
Our corporate customers can request a summary of our latest penetration test report under a signed NDA. Copies of our ISO 27001 and ISO 9001 certificates can also be shared upon request. For requests related to security documents, you can write to info@vitarnd.com.
If you discover a vulnerability on vita platforms, please report it to our security team. All reports submitted under our responsible disclosure policy are carefully reviewed and answered. We support good-faith security researchers.
Security reports are answered within 72 hours. No legal action is taken against research that does not involve abuse.
You can also write to the same address for penetration test reports and certification documents.