VinaFi combines 24-hour inventory surveillance with platform-level SOC 2 Type II infrastructure, AES-256 encryption, and strict row-level portfolio isolation.
SOC 2 Type II Certified Infrastructure (Private Server / AWS)
ISO/IEC 27001 Compliant Datacenters
AES-256 Data Encryption at Rest
TLS 1.3 Encryption in Transit
Security Architecture
Each layer is independently engineered and continuously enforced — so no single control carries the whole trust burden.
Hosted on independently audited SOC 2 Type II and ISO 27001 certified cloud infrastructure.
All floorplan, VIN, and lender data encrypted in transit (TLS 1.3) and at rest (AES-256).
Automated Row-Level Security (RLS) ensures complete data separation — Lender A can never query or view Lender B's portfolio or payoff data.
Automated static code analysis (SAST), API secret detection, and dependency vulnerability scans run on every update.
48-hour physical photo dispatches enforce hardware GPS locking and automated VIN OCR to eliminate manual lot fraud.
Every daily delta update requires manual verification and produces an audited, timestamped paper trail.
Subprocessor Transparency
A complete, public directory of the core subprocessors that power the VinaFi platform.
| Subprocessor | Purpose | Location | Security Certification |
|---|---|---|---|
| Private Server / AWS | Cloud Application & Compute Hosting | USA | SOC 2 Type II, ISO 27001 |
| Managed PostgreSQL | Primary Relational Database & Audit Logs | USA | SOC 2 Type II, AES-256 |
| Cloudflare | Edge Network, WAF, SSL/TLS, DDoS Defense | Global | SOC 2 Type II, PCI-DSS |
| ZenRows | Emergency Fallback Proxy Network | USA / EU | TLS 1.3, Data Isolation |
Cloud Provider
Amazon Web Services
Region Redundancy
Multi-AZ, geo-replicated
Uptime Target
High-availability architecture
Cipher Standard
AES-256 / TLS 1.3
We do not sell your data.
Vinafi will never sell, rent, or trade your organization's data or your customers' data to third parties under any circumstances.
Legal cooperation only when required.
We cooperate with government agencies only when legally required through proper legal process — valid subpoenas, court orders, or search warrants — and will notify affected users unless prohibited by law.
Purpose-built data usage.
All vehicle, lien, and financial data is used exclusively to provide the services you've contracted with us. Full data export and deletion capabilities are available upon request.
Our security team is available to answer questions about our infrastructure, compliance posture, or data handling policies.