Security
Security before exposure.
VNet is designed so that protection happens first: information is classified, policy is evaluated and authorization is checked before anything leaves a protected environment.
Security before exposure
Protect the data before it leaves.
Most systems let information out first and try to secure it afterwards. VNet evaluates policy, identity, permissions and sensitivity before protected information is sent to another application, an AI model, another person or an external service.
The information may travel as requested — the policy, the identity and the destination all agree.
It travels in a protected form: sensitive elements are removed or masked before anything leaves.
It does not leave. The request is refused and recorded, and you can see why.
Per-item encryption
Protected items are encrypted individually rather than as one large store, so access can be granted, limited and revoked item by item.
Sensitive-data classification
Information is classified by sensitivity — personal, health, financial, legal, organizational — so policies can treat each kind appropriately.
Policy-controlled AI access
What an AI model may receive is decided by policy, not by whichever application happens to hold the data.
Identity-aware permissions
Permissions follow your verified VNet identity and your role in each organization, not a device or a shared password.
Secure third-party application sessions
External web applications open inside controlled sessions so your VNet identity and data are not exposed to them by default.
Immutable security and audit records
Security-relevant events are recorded in tamper-evident, signed logs that can be verified later.
Device trust and biometric step-up
Sensitive actions can require a trusted device and a biometric or second-factor confirmation at the moment they happen.
Controlled sharing and document authenticity
Sharing is explicit and revocable, and documents can be signed with a VNet identity and verified for authenticity.
Built into the platform
Per-item encryption
Protected items are encrypted individually, so access is granular and revocable.
Sensitive-data classification
Personal, health, financial, legal and organizational data are recognized and treated by policy.
Policy-controlled AI access
What a model may receive is decided by policy, never by the application alone.
Identity-aware permissions
Access follows your verified identity and your role in each organization.
Secure third-party sessions
External web applications open in controlled sessions that do not expose your VNet identity by default.
Immutable audit records
Security events are written to signed, tamper-evident logs.
Device trust
Sensitive actions can be limited to devices you have trusted.
Biometric step-up
A biometric or second factor is asked for at the moment a sensitive action happens.
Document authenticity
Documents signed with a VNet identity can be verified for authenticity.
Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability in VNet, contact us through the Trust Center and we will acknowledge your report and work with you on a coordinated fix.
We do not publish confidential algorithms, security implementation secrets, encryption keys or internal architecture details that would increase the attack surface of the platform.