Vyso / security

Security without the theatre.

A practical overview of how Vyso handles account access, network transport, customer content, and automated processing.

01 / Infrastructure

A small, deliberate service surface.

Vyso runs a public web application, authenticated account surfaces, a Developer API, and a CDN delivery layer. Public traffic is routed through Cloudflare. We do not publish private network details or operational credentials on this page.

02 / Transport

Encrypted connections by default.

Connections to vyso.io, the Developer API, and CDN delivery use HTTPS and TLS. Storage and processing controls can depend on the service component and infrastructure used for a workspace, so we do not make a blanket encryption-at-rest claim beyond the controls confirmed for the relevant service.

03 / Authentication

Account access is handled by Clerk.

Vyso uses Clerk for sign-in, sign-up, and session management. Authenticated API operations are scoped to the account or workspace represented by the session. Keep your account credentials private and report unexpected account activity to us promptly.

04 / Customer data

Access follows the service boundary.

Uploaded media and metadata are used to provide the requested library, search, transformation, and delivery features. Workspace operations in the Developer API are scoped to the authenticated workspace. Deletion and retention are described in the Privacy Policy and applicable plan or service settings.

05 / Automated processing

Automation stays reviewable.

Vyso may use automated processing to generate captions, tags, search signals, similarity results, or cleanup suggestions. Automated results can be incomplete, and people remain responsible for reviewing important decisions before deleting or publishing assets.

Report a concern

Found something that needs attention?

Email [email protected] with “Security” in the subject. Do not include passwords, tokens, or private customer content.

Read the Privacy Policy