Skip to content

What we actually do.

Vemon serves public data, so the stakes here are availability and integrity rather than confidentiality. This page describes the current state, not an aspiration.

In place

Today

Transport

TLS 1.3 on every endpoint. HSTS enabled. No plaintext fallback.

API keys

Stored hashed, shown once at creation, revocable immediately.

Request logging

Method, path, key ID, latency, and status retained 90 days.

Parameter allowlist

Endpoints reject unknown parameters rather than ignoring them.

Rate limiting

Per-key and per-address, enforced at the edge.

Dependency scanning

Automated alerts on advisories affecting locked versions.

Not yet

What we do not have

Stated because a security page that lists only strengths is not useful to anyone evaluating it.

  • No SOC 2 report
    We have not begun an audit. When we do, this page will name the auditor and the period.
  • No HIPAA posture
    Vemon processes no protected health information. The data we serve is published federal aggregate data. If that ever changes, this section changes first.
  • No SLA on free plans
    Uptime commitments begin with Enterprise agreements.
  • No SSO or SCIM
    Planned for Business and Enterprise, not built.

Reporting

Found something?

Email security@vemon.io. We acknowledge within two business days and will keep you updated until it is resolved.

Please do not run automated scanning against the production API — it trips the rate limiter and tells you nothing we would not tell you directly. If you need a higher limit to test something, ask.

We do not currently operate a paid bounty programme. We do credit reporters who want to be credited.