Trust Center
How VNet earns trust.
Security, privacy, responsible AI, disclosure and status — in one place, kept current by VNet World Corp.
Security overview
Policy before egress, per-item encryption, identity-aware permissions, device trust and step-up authentication.
Read →
Privacy principles
User control, data minimization, explicit authorization and transparent AI access.
Read →
Encryption overview
Protected items are encrypted individually; keys are managed by the platform and never published.
Responsible AI
AI output is labeled, governed by policy and sensitivity, and never trained on your protected data without authorization.
Vulnerability disclosure
Report a suspected vulnerability through the contact form (topic “Security disclosure”). We acknowledge reports and coordinate fixes.
Report →
Compliance and certification status
VNet is designed to support compliance with relevant frameworks. Independent certifications are listed here only once completed; none is implied.
Data residency
Residency options are offered where implemented; ask us about your region.
Subprocessors
The infrastructure and AI providers VNet relies on are disclosed to organizations on request and governed by policy.
Service status and advisories
Service status and security advisories are published here as they occur.
Legal documentation
Terms, privacy notice and intellectual-property information.
Read →
Frequently asked
Is VNet certified against a security standard?
We only state a certification once it has been completed with an independent assessor. Until then we say “designed to support compliance with”, which is what it means.
Does VNet train AI models on my data?
Protected data is not used to train models without explicit authorization. AI access is governed by policy and sensitivity and is visible to you.
Where is my data stored?
On VNet’s cloud infrastructure with regional options where implemented. Organizations can ask about residency for their region.
One standard, every application.
VMail, VHealth, VFinance, VFile and every other VNet application run on one platform, so they inherit the same protections. Classification, policy evaluation, per-item encryption, identity-aware permissions and audit records are not built application by application — they belong to VNet itself.
That is what makes this page possible: a commitment made here holds everywhere you work, not only in the application that happened to make it.
If something goes wrong
We contain it first.
The first priority is stopping exposure — revoking access, isolating the affected component, and preserving the audit record of what happened.
We tell the people affected.
The people and organizations whose data is involved hear from us directly: what we know, what we do not yet know, and anything we need them to do.
We publish what we learned.
Advisories are posted here with the cause and the fix. We withhold implementation detail that would put other people on the platform at risk.
Working with us
Security researchers
Send a report through the contact form under “Security disclosure”. We acknowledge it, keep you updated while the fix is made, and credit you if you would like to be named.
Organizations in review
Ask for the security overview, the subprocessor list and residency options for your region. We answer questionnaires with what is true today, and mark work in progress as in progress.
People using VNet
Ask what VNet holds about you, correct it, export it or have it removed. Requests go through the contact form and are handled by VNet World Corp.
What we publish, and what we don’t
Published here
- How security and privacy actually work, in plain language
- The current state of every compliance framework we are pursuing
- Service status and security advisories, as they occur
- Subprocessors and data residency options, to organizations on request
- Terms, privacy notice and intellectual-property information
Deliberately withheld
- Encryption keys and key-management secrets
- Confidential algorithms and internal architecture detail
- The specifics of an unfixed vulnerability, until a fix is available
- Anything that would expose one customer’s data to another
These are withheld to protect the people on the platform, not the company.
Trust is earned in the open.
This page is maintained by VNet World Corp and updated as status changes — including when the change is not good news. If something here is unclear, incomplete or out of date, tell us.