VATFIND LEGAL
Security information
Account, workspace and integration controls, plus how to report a VATFind security issue.
Updated 8 September 2026
Account and workspace access
VATFind uses WorkOS for sign-in and verified account identity. New customers returning from a confirmed payment can access their newly created account through a secure session tied to the checkout browser. This does not verify the checkout email or grant access to an existing account. Workspace requests check the signed-in identity, and account-owned history, saved results and support attachments are restricted to the authorised owner or designated staff where the function requires it. Access to a live API or monitoring check also depends on the credential scope, account status and allowance.
Keep your sign-in method secure, grant access only to authorised people and revoke API keys or MCP connections you no longer need. VATFind support will not ask you to send your password, a full payment-card number or a secret API key.
Payments, tokens and delivery
Stripe handles payment-card collection. VATFind verifies signed payment events before updating entitlement records and maintains event references to reduce duplicate fulfilment. API keys and OAuth credentials have permissions and revocation controls. MCP authorisation uses scoped access and expiring tokens.
Support screenshots use private object storage with an ownership or staff-authorisation check before delivery. Configured monitoring webhooks use signed event payloads. Customers should verify webhook signatures and protect their receiver. HTTPS protects traffic in transit on the public service.
Scope of security assurances
These statements describe application controls. An uptime commitment, data-residency promise, certification, independent penetration-test result, recovery objective or specific backup schedule applies only where VATFind supplies supporting evidence and expressly agrees it for your service. Request the evidence needed for your procurement review through the contact details below.
The privacy notice explains retention and rights; the provider inventory identifies the supporting services. Security depends on your account, integrations and exported copies as well as VATFind’s controls.
Report a vulnerability or incident
To email VATFind, click here with “VATFind security” in the subject. Include the affected URL or request reference, time, impact and safe steps to reproduce. Share the minimum information needed and redact secrets and other people’s data.
Do not exploit an issue further, access another person’s information, disrupt service or publicly disclose sensitive details before we have had a reasonable opportunity to investigate. This reporting route does not authorise intrusive testing or create a paid bounty programme. Contact us to agree any testing scope.
We will assess the report and provide the incident notifications required by law or an applicable data processing agreement. An incident involving Customer-controlled data is notified without undue delay under the agreed processor terms.