Security & Privacy
How the platform protects accounts and data, and what we do with your information.
10 articles · Written for: Everyone
Platform Security
Security and privacy
How Metric Vault protects your account, what data it stores and for how long, who else touches it, and how to exercise your data rights.
How we protect your account
The protections actually in place around a Metric Vault account: managed sign-in, encrypted transport, server-side entitlement checks, account scoping and Stripe-handled payments.
Authorization model
Every authorization gate in the platform, the exact resources each one protects, the denial it returns, and how each behaves when its dependency is unavailable.
Security headers and CSP
The complete response-header inventory for the platform: what the _headers file declares, which of those declarations survive to the browser, what the worker sets itself, and what is not set at all.
API key security
How Metric Vault API keys are generated, issued, stored, verified and revoked today, and the operational handling that follows from them being bearer credentials.
Security best practices for your team
The practical controls you own rather than we do: password and sign-in hygiene, seat reviews, share-link discipline, key rotation, and what to do first if something looks wrong.
Privacy & Data
What data we store
Every category of information Metric Vault holds, why it is held, where it lives, and what is deliberately never stored on our systems.
Data retention and deletion
How long Metric Vault keeps each kind of data, what deletes itself, what waits for you to delete it, and exactly how to have an account and its data removed.
GDPR and compliance
The data protection commitments Metric Vault makes under GDPR, UK GDPR and CCPA, how international transfers are covered, and the exact route for a rights request.
Subprocessors and data flow
Every outside service involved in delivering Metric Vault, exactly what each one receives, and what never leaves the platform.