# Security and data protection

Vintage is built so that the personal information in your loan files never reaches it. Personal information is removed, and your loan and tax identifiers are scrambled, **in your browser, before anything is uploaded**. Each protection is stated here in terms you can rely on and check, and only as Vintage does it today.

## What never leaves your browser

When you choose a file, the **Remove PII** step runs in your browser, once for each file group (Snapshot, Origination, or Transaction files):

- Columns you mark as personal information (PII), such as names, addresses, or phone numbers, are **dropped from the file before upload**.
- The **Loan ID** and **Tax ID** columns are replaced by **protected IDs**, one-way scrambled values that cannot be turned back into the originals.
- Only the resulting scrubbed file is uploaded.

So Vintage never receives raw personal information, raw Loan ID values, or raw Tax ID values. Excel workbooks are read entirely in your browser too; Vintage receives only the scrubbed result.

Vintage remembers your choices for the next upload of a file it recognizes: which column was the Loan ID, which was the Tax ID, and which columns you removed. What it remembers is **column names and your designations, never a cell value**. The contents of a removed column never leave your browser. See [Removing personal information](/uploading/removing-personal-information/).

## Protected IDs

A **protected ID** is the scrambled stand-in for a Loan ID or Tax ID. Within your organization, the same identifier always becomes the same protected ID, which is what lets Vintage recognize the same loan in next month's file without ever holding the real number.

- Before scrambling, a Loan ID is **normalized** so cosmetic differences do not split one loan's history: whitespace is removed, letters match regardless of case, and leading zeros are dropped. Every other character stays significant.
- **A placeholder is never scrambled into an ID.** Values such as `N/A`, `NULL`, a lone `-`, or all zeros give the row no protected ID, because every placeholder would otherwise scramble to the same value and merge many different loans into one.
- **Tax ID is scrambled and stored, and serves as a fallback join key.** Loan ID is the primary key that identifies a loan.
- The Portfolio screen shows only protected IDs, never a raw loan number or tax ID, and you search loans by protected ID.

## The safety net after upload

As a backstop, Vintage re-checks a sample of each uploaded, already-scrubbed file for columns whose values still look like personal information, such as an email address, phone number, or Social Security number you forgot to remove. A column it is confident about is **excluded automatically** on the Column Mapping screen, which tells you plainly which columns were dropped and why. You can include any of them again.

This check can only **add** exclusions. Neither it nor Vintage's memory of earlier uploads can ever take a column out of the set you chose to remove. The protected Loan ID and Tax ID columns are never flagged. The browser step, with your review, remains the protection; the re-check is a second line behind it, and when it cannot run for a file, it is skipped for that file.

## What Vintage stores

- **The scrubbed files** you upload, and the values from each of their rows, kept tied to the upload, file, row, and column they came from. This **source data** is what lets Vintage show where any figure came from and rebuild your portfolio when something changes.
- **Protected IDs**, in place of your identifiers.
- **Your decisions**: column mappings, value classifications, declared formats, and the PII designations described above.

Your **original, unscrubbed files are never stored**, because they contain personal information. That is why a draft you leave can be resumed once its files have been uploaded, but never back at file selection.

A **draft** upload stays available to resume until you finalize it or delete it. It does not expire.

## Deletion and retention

You can delete an upload, or one file in it, at any time, whether it is a draft or accepted. Deletion takes effect as soon as you confirm: the data no longer contributes to readiness, modeling, or pricing, and Vintage rebuilds your portfolio without it in the background. Until that finishes, the Portfolio and Modeling screens say they are updating rather than showing the old numbers as current.

Deletion keeps an audit history:

| What | How long it is kept after deletion |
|---|---|
| The deleted rows' cell values | Purged **90 days** after deletion |
| The upload's row and column records, and its scrubbed file | Kept indefinitely for audit |
| Data you have not deleted | Never purged; it is the basis for your portfolio |

Keeping audit records is the default, not a condition of using Vintage. **Your organization can request permanent deletion of its data at any time**, and Vintage then removes the retained files and audit records too. This is handled as a request to the Vintage team rather than a button in the product. See [Upload History](/uploading/upload-history/).

## Who can see your data

**Your organization's data is shown only to its current members.** Every portfolio, upload, field, and segment belongs to exactly one organization, and Vintage never shows it to a person who is not a member. Within the organization, each member's **role** (admin, editor, or viewer) decides what they can change; see [Roles and permissions](/reference/roles-and-permissions/).

When your organization is new, a Vintage teammate joins it as an **editor** to finish setting up the first portfolio. They are listed on your Team page as **Vintage support**, your admin can remove them at any time, and they leave when the work is done. See [Your first upload](/uploading/your-first-upload/).

## Restricting access by network

An admin can limit which networks reach the organization with an **IP allowlist**, under Settings › Security. Rules are individual addresses or ranges in CIDR notation (an address followed by a slash and a prefix length, such as `203.0.113.0/24`), IPv4 or IPv6.

- With **no rules**, the organization is reachable from any network. This is the default.
- With **one or more rules**, only a connection from a matching address can reach the organization's signed-in pages and its data. Requests from other addresses are refused, not merely hidden.
- Vintage **refuses to save** a list that would not include the admin's own current address, and names the address to add, so an admin cannot lock themselves out.
- Someone connecting from a disallowed address sees a page that explains this and **shows their own address**, never the allowlist. From there they can switch to another organization they belong to, sign out, or email support.

## Accounts and sessions

- **Email verification is required.** A new account confirms its address with a 6-digit code before it can use Vintage. Codes expire after a short window, and wrong attempts are limited.
- **Sessions last 60 days and roll forward with use.** Someone who keeps working is never asked to sign in again; 60 days without activity ends the session. Signing out ends it at once.
- **Sign out of all other devices** in Settings › Profile ends every session except the one you are using. The other devices are signed out the next time they are used.
- **Resetting a forgotten password** ends every other session on the account and signs you in on the device you reset from. The reset link expires after one hour, and the request page never reveals whether an address has an account. **Changing** your password from Settings does not sign out other devices; use **Sign out of all other devices** for that.
- **Changing your login email needs proof of both mailboxes**: a code sent to your current address, then a code sent to the new one. Someone using a signed-in browser cannot move your account to an address of their own, and the code to your current address doubles as a warning.
- When a session ends while Vintage is open, you are returned to the sign-in screen, and after signing in you are taken back to where you were.

**Note:** These are the controls Vintage describes as part of the product. For anything your security review needs that is not covered here, ask the Vintage team.

## Related

- [Removing personal information](/uploading/removing-personal-information/)
- [Roles and permissions](/reference/roles-and-permissions/)
- [Signing in and sessions](/account/signing-in-and-sessions/)
- [Team and organization settings](/account/team-and-organization-settings/)
- [Upload History](/uploading/upload-history/)