We built VIQ for business owners who can't afford a data breach. Every layer of the platform — from password hashing to Stripe payments — is designed with security first.
Passwords are hashed using PBKDF2-SHA-256 with 100,000 iterations and a unique 16-byte random salt per user — computed in our Cloudflare Worker, never in the browser.
All payment processing is handled end-to-end by Stripe. VIQ never receives, processes, or stores any credit card data.
User sessions are signed JWT tokens issued by our Cloudflare Worker using HMAC-SHA-256. Tokens expire after 30 days.
All traffic between your browser, our platform, and third-party APIs runs over TLS 1.3. Our Cloudflare Worker enforces strict CORS origin controls.
viq.vendorintel.ai originYour vendor and business data is stored in our RESTful database, served over HTTPS. Database access is scoped to your account via session credentials.
Your vendor spend data is used exclusively to power your VIQ scores. We do not sell, license, or share individual business data with any third party.
When you use VIQ to score, benchmark, or flag a vendor, that vendor is never notified, contacted, or given access to your data or your scores. Your spend amounts, contract terms, risk ratings, and negotiation notes are visible only to you and the team members you explicitly authorize.
VIQ does not aggregate, anonymize, or resell individual vendor performance data to any party — including the vendors being evaluated. We do not accept payment from vendors for score visibility, preferential ranking, or any other placement. Our only customer is you.
No credit card required. Your data is protected from day one.