Security at Varhugi
Varhugi trains staff in security awareness, so it is fair to ask how the service itself is protected. This is the overview a security manager or procurement team needs when assessing a vendor: hosting, access control, technical safeguards and data handling.
Hosting and data storage
The service runs on Vercel and all data is stored in a PostgreSQL database at Neon in Frankfurt, Germany, within the European Economic Area. Email, such as sign-in links and reminders, is sent through Resend.
Some subprocessors are US companies. Where personal data is transferred outside the EEA, the transfer relies on the European Commission's Standard Contractual Clauses (SCC) or the subprocessor's participation in the EU-US Data Privacy Framework.
Sign-in and access control
No passwords
Varhugi stores no passwords. Sign-in happens via a verification link sent by email or through your workplace identity provider, so there is no password database that can leak.
SSO with Microsoft and Google
Staff can sign in with their workplace Microsoft Entra ID or Google account. Your company's access control applies unchanged, including when an employee's account is disabled.
Role-based permissions
Permissions follow roles. Regular staff see only their own training, and administrators see the status of their own company, no one else's.
Tenant isolation
Each company's data is separated from every other's, and all queries are scoped to the signed-in user's company.
Technical safeguards
- Encryption in transit and at rest: all traffic runs over TLS and database contents are encrypted at rest.
- Security headers on every page, including X-Frame-Options: DENY, nosniff, Referrer-Policy and Permissions-Policy.
- Rate limiting on sign-in and other sensitive endpoints protects against guessing attempts and abusive traffic.
- Security updates to software dependencies are part of the service's regular maintenance.
Security review
A thorough security review of the service's entire codebase was carried out in July 2026 and the resulting fixes were shipped. The review is repeated regularly.
If you find a vulnerability in the service, we welcome a report via the Contact page and will respond quickly.
Subprocessors
Varhugi uses a small set of well-known subprocessors. Each receives only the data its service requires and is bound by a data processing agreement with Varhugi. Customers are notified of changes to this list 30 days in advance.
- VercelHosting and running the application
- NeonDatabase, hosted in Frankfurt
- ResendSending email
- StripePayment processing when a subscription is paid
- UpstashCache for rate limiting
Data retention and deletion
At the end of the service, or on request, personal data is deleted within 30 days or returned in a common machine-readable format. Issued certificates are retained so they can be verified on the public verification page, but are deleted on specific request.
Security incidents
If a breach affecting a customer's data is detected, the customer is notified without undue delay, with a description of the nature of the breach, its likely impact and the measures taken. This lets the company meet its own 72-hour notification duty to the Icelandic Data Protection Authority where applicable.
Related documents
The Data Processing Agreement applies automatically to every company using the service. Pro customers can request a countersigned copy.
Questions about security? We answer them via the Contact page.

