What we actually do.
Vemon serves public data, so the stakes here are availability and integrity rather than confidentiality. This page describes the current state, not an aspiration.
In place
Today
Transport
TLS 1.3 on every endpoint. HSTS enabled. No plaintext fallback.
API keys
Stored hashed, shown once at creation, revocable immediately.
Request logging
Method, path, key ID, latency, and status retained 90 days.
Parameter allowlist
Endpoints reject unknown parameters rather than ignoring them.
Rate limiting
Per-key and per-address, enforced at the edge.
Dependency scanning
Automated alerts on advisories affecting locked versions.
Not yet
What we do not have
Stated because a security page that lists only strengths is not useful to anyone evaluating it.
- No SOC 2 reportWe have not begun an audit. When we do, this page will name the auditor and the period.
- No HIPAA postureVemon processes no protected health information. The data we serve is published federal aggregate data. If that ever changes, this section changes first.
- No SLA on free plansUptime commitments begin with Enterprise agreements.
- No SSO or SCIMPlanned for Business and Enterprise, not built.
Reporting
Found something?
Email security@vemon.io. We acknowledge within two business days and will keep you updated until it is resolved.
Please do not run automated scanning against the production API — it trips the rate limiter and tells you nothing we would not tell you directly. If you need a higher limit to test something, ask.
We do not currently operate a paid bounty programme. We do credit reporters who want to be credited.