Security posture
Security and privacy
VAT Engine is built with account isolation, scoped API keys, session and CSRF protections, rate limiting, activity logs, and security-focused operational controls. Those controls reduce risk; they are not a guarantee that the alpha service is suitable for every use case.
What this helps you do
Understand the public safeguards and limits before connecting business data or relying on the service in a production process.
- Scoped API-key generation, rotation, and revocation.
- Account security controls including two-factor authentication.
- Privacy-aware consent and telemetry boundaries.
- Report security concerns or public-data issues through the responsible contact channel.