Alpha testing: all current functionality is free while VAT Engine is in active development

Security posture

Security and privacy

VAT Engine is built with account isolation, scoped API keys, session and CSRF protections, rate limiting, activity logs, and security-focused operational controls. Those controls reduce risk; they are not a guarantee that the alpha service is suitable for every use case.

What this helps you do

Understand the public safeguards and limits before connecting business data or relying on the service in a production process.

  • Scoped API-key generation, rotation, and revocation.
  • Account security controls including two-factor authentication.
  • Privacy-aware consent and telemetry boundaries.
  • Report security concerns or public-data issues through the responsible contact channel.

How to use it well

Minimize access

Create only the API keys and account access needed for a workflow, then rotate or revoke them when their purpose ends.

Protect the account boundary

Use a unique password and two-factor authentication, and do not place keys in browser code, public repositories, or support messages.

Use the right reporting channel

Send a concise description of a security concern to the responsible contact path without including customer data, keys, or exploit details in public channels.