Security & data

Keep your operational data under your control

Vasco limits access by account, company and role. This page explains the controls available now, what your team needs to manage, and how to report a concern—without promising absolute security.

Available today

Controls you can verify in the product

We only describe controls available in the current Vasco app and policy. The screens and actions available still depend on the account type, role and modules in use.

01

Company data boundaries

After sign-in, data requests are scoped to the company linked to the account. Accounts from another company do not share the same workspace.

02

Role-based access

Screens and actions follow the account's role and permissions. Owners, admins and workers do not automatically receive the same access.

03

History for selected actions

Selected workflows, including approvals and important changes, keep who acted and when. Coverage follows the workflow in use; this is not a claim that every click is recorded.

04

Encrypted connections in transit

Connections between the app and Vasco services use HTTPS while data is sent. This protects data in transit, but it is not a promise that every security risk can be eliminated.

05

Owner-controlled exports

Owners can export available company datasets from the app into spreadsheet-compatible files. Export coverage follows the modules and data available to the account.

06

In-app account deletion

Owners can start company deletion, while workers can delete their login account. Some records may be retained when the company or the law requires it.

Shared responsibility

Technical controls still need good team habits

  1. 1

    Give access according to each person's job; do not share one account across several people.

  2. 2

    Keep passwords, worker codes, invitation codes and sign-in links from being shared carelessly.

  3. 3

    Change or remove access promptly when someone changes role or leaves the company.

  4. 4

    Review the data entered by your team and keep any needed export before deleting or moving an account.

  5. 5

    Report suspicious access without sending passwords or sign-in codes to anyone, including the Vasco team.

Data and accounts

You can take your data and manage the end of access

Data export

Owners can open app settings and export the available company datasets. Export before moving systems or deleting an account when your company needs a copy.

Account deletion

Owners and workers can start deletion from the app. What is removed or retained depends on the account type and any company or legal obligations.

See deletion instructions

Privacy policy

The privacy policy explains data categories, processing purposes, service providers, user choices, retention and how to make a data request.

Read the full policy

Report a concern

Seen access that does not look right?

Send a report through Vasco's official channel. We will review the account context and ask for more information when needed.

Include:

  • the company name and affected account email;
  • the time of the event and its time zone;
  • the page or feature being used; and
  • a reproducible summary, with screenshots that contain no access secrets.
halo@vasco.id

Do not send passwords, sign-in codes, worker codes, invitation codes or private access links.

Discuss your company's access needs

Tell us how your team is structured and which workflows need limits. We will show the available controls, including their boundaries, during the first consultation.