Security
Last updated: July 22, 2026
This page summarizes the safeguards MyVisito uses to protect data and explains how to report a suspected security vulnerability responsibly.
How we protect your data
- Encryption in transit: traffic to and from MyVisito is encrypted using TLS.
- Encryption at rest: your data is stored with encryption at rest through our infrastructure providers.
- Workspace access controls: database-level access policies and user roles are used to restrict access according to the relevant workspace.
- Account protection: our authentication provider stores passwords as one-way hashes, not as readable plain text.
- Payments: card payments are handled by Stripe, a PCI DSS Level 1 service provider. MyVisito does not store your full card number.
- Production access: access to production systems is limited to authorized operational needs.
Reporting a security issue
If you believe you have found a security vulnerability, send a clear description, the minimum steps needed to reproduce it, and the affected page or feature. You may report without providing your name.
Do not send passwords, authentication tokens, API keys, full payment card details, or personal data belonging to other people. Redact sensitive information from screenshots and send an initial description without sensitive material. We will tell you if more information is needed.
Testing guidelines
- Only test accounts and data that you own or have explicit permission to use.
- If you encounter data that is not yours, stop immediately. Do not copy, download, change, delete, or share it. Report the issue using the minimum information needed.
- Use the smallest non-destructive proof needed to confirm an issue. Do not maintain access or use a vulnerability beyond that confirmation.
- Do not run denial-of-service or load attacks, disruptive automated scans, spam, phishing, social engineering, malware, or physical attacks.
- Third-party services are outside this policy. Follow the security and testing policies published by their providers.
- Give us a reasonable time to investigate and fix an issue before sharing it publicly.
Our commitment to researchers
If you act in good faith, follow these guidelines and applicable law, avoid harm, and report promptly, we will not initiate or support legal action solely for research that complies with this policy. This authorization applies only to MyVisito systems and to accounts and data you are permitted to use. Activity outside these guidelines is not authorized. If you are unsure whether a test is permitted, contact us before testing.
We aim to acknowledge valid reports within five business days and to provide updates while we investigate. We do not currently operate a paid bug bounty, and submitting a report does not create a right to payment. With your permission, we may credit helpful researchers after an issue is resolved.
More information
For how we handle personal information, see our Privacy Policy. For anything else, contact support@myvisito.com, or write to: EmodeFlow, LLC, 1111b South Governors Avenue, Suite 93153, Dover, DE 19904, United States.