Security

How your local's data stays protected

You're trusting Vorialis with real member questions and grievances. Here's what's actually protecting that data, explained without the jargon.

Your data, walled off

Every local's questions, grievances, and contract data live in their own separate, locked-down section of the database. There's a rule built into the database itself — not just the app on top of it — that only lets a request see data belonging to its own organization. One local's data structurally cannot leak into another's view. It's enforced automatically, every time, not a setting that can be forgotten.

Admin access, locked down

Anyone with administrator access has to prove who they are through a password check that happens on our servers, not just in their browser. Once verified, they're issued a signed session token — a temporary, tamper-proof pass. If someone tried to fake or alter it, the system rejects it immediately. The same category of protection banking apps use.

Encrypted, always

Data is encrypted the entire time it exists in our system. While it's traveling — from a member's phone to our servers — it moves over HTTPS, the same standard used by banks and any site with a padlock icon in the browser bar. While it's stored, the database keeps everything encrypted by default.

Never sold, ever

Vorialis doesn't sell member data, share it with advertisers or data brokers, or use it to build shared models across organizations.

A note on scope

Security isn't a one-time checklist — it's something we keep paying attention to as Vorialis grows. This page describes the protections in place today. If you're a local considering Vorialis and want more detail than what's written here, we're happy to walk through it directly.