Minimize access
Create only the API keys and account access needed for a workflow, then rotate or revoke them when their purpose ends.
Alpha testing: all current functionality is free while VAT Engine is in active development
Security posture
VAT Engine is built with account isolation, scoped API keys, session and CSRF protections, rate limiting, activity logs, and security-focused operational controls. Those controls reduce risk; they are not a guarantee that the alpha service is suitable for every use case.
Understand the public safeguards and limits before connecting business data or relying on the service in a production process.
Create only the API keys and account access needed for a workflow, then rotate or revoke them when their purpose ends.
Use a unique password and two-factor authentication, and do not place keys in browser code, public repositories, or support messages.
Send a concise description of a security concern to the responsible contact path without including customer data, keys, or exploit details in public channels.