Security and data protection
Vintage is built so that the personal information in your loan files never reaches it. Personal information is removed, and your loan and tax identifiers are scrambled, in your browser, before anything is uploaded. Each protection is stated here in terms you can rely on and check, and only as Vintage does it today.
What never leaves your browser
Section titled “What never leaves your browser”When you choose a file, the Remove PII step runs in your browser, once for each file group (Snapshot, Origination, or Transaction files):
- Columns you mark as personal information (PII), such as names, addresses, or phone numbers, are dropped from the file before upload.
- The Loan ID and Tax ID columns are replaced by protected IDs, one-way scrambled values that cannot be turned back into the originals.
- Only the resulting scrubbed file is uploaded.
So Vintage never receives raw personal information, raw Loan ID values, or raw Tax ID values. Excel workbooks are read entirely in your browser too; Vintage receives only the scrubbed result.
Vintage remembers your choices for the next upload of a file it recognizes: which column was the Loan ID, which was the Tax ID, and which columns you removed. What it remembers is column names and your designations, never a cell value. The contents of a removed column never leave your browser. See Removing personal information.
Protected IDs
Section titled “Protected IDs”A protected ID is the scrambled stand-in for a Loan ID or Tax ID. Within your organization, the same identifier always becomes the same protected ID, which is what lets Vintage recognize the same loan in next month’s file without ever holding the real number.
- Before scrambling, a Loan ID is normalized so cosmetic differences do not split one loan’s history: whitespace is removed, letters match regardless of case, and leading zeros are dropped. Every other character stays significant.
- A placeholder is never scrambled into an ID. Values such as
N/A,NULL, a lone-, or all zeros give the row no protected ID, because every placeholder would otherwise scramble to the same value and merge many different loans into one. - Tax ID is scrambled and stored, and serves as a fallback join key. Loan ID is the primary key that identifies a loan.
- The Portfolio screen shows only protected IDs, never a raw loan number or tax ID, and you search loans by protected ID.
The safety net after upload
Section titled “The safety net after upload”As a backstop, Vintage re-checks a sample of each uploaded, already-scrubbed file for columns whose values still look like personal information, such as an email address, phone number, or Social Security number you forgot to remove. A column it is confident about is excluded automatically on the Column Mapping screen, which tells you plainly which columns were dropped and why. You can include any of them again.
This check can only add exclusions. Neither it nor Vintage’s memory of earlier uploads can ever take a column out of the set you chose to remove. The protected Loan ID and Tax ID columns are never flagged. The browser step, with your review, remains the protection; the re-check is a second line behind it, and when it cannot run for a file, it is skipped for that file.
What Vintage stores
Section titled “What Vintage stores”- The scrubbed files you upload, and the values from each of their rows, kept tied to the upload, file, row, and column they came from. This source data is what lets Vintage show where any figure came from and rebuild your portfolio when something changes.
- Protected IDs, in place of your identifiers.
- Your decisions: column mappings, value classifications, declared formats, and the PII designations described above.
Your original, unscrubbed files are never stored, because they contain personal information. That is why a draft you leave can be resumed once its files have been uploaded, but never back at file selection.
A draft upload stays available to resume until you finalize it or delete it. It does not expire.
Deletion and retention
Section titled “Deletion and retention”You can delete an upload, or one file in it, at any time, whether it is a draft or accepted. Deletion takes effect as soon as you confirm: the data no longer contributes to readiness, modeling, or pricing, and Vintage rebuilds your portfolio without it in the background. Until that finishes, the Portfolio and Modeling screens say they are updating rather than showing the old numbers as current.
Deletion keeps an audit history:
| What | How long it is kept after deletion |
|---|---|
| The deleted rows’ cell values | Purged 90 days after deletion |
| The upload’s row and column records, and its scrubbed file | Kept indefinitely for audit |
| Data you have not deleted | Never purged; it is the basis for your portfolio |
Keeping audit records is the default, not a condition of using Vintage. Your organization can request permanent deletion of its data at any time, and Vintage then removes the retained files and audit records too. This is handled as a request to the Vintage team rather than a button in the product. See Upload History.
Who can see your data
Section titled “Who can see your data”Your organization’s data is shown only to its current members. Every portfolio, upload, field, and segment belongs to exactly one organization, and Vintage never shows it to a person who is not a member. Within the organization, each member’s role (admin, editor, or viewer) decides what they can change; see Roles and permissions.
When your organization is new, a Vintage teammate joins it as an editor to finish setting up the first portfolio. They are listed on your Team page as Vintage support, your admin can remove them at any time, and they leave when the work is done. See Your first upload.
Restricting access by network
Section titled “Restricting access by network”An admin can limit which networks reach the organization with an IP allowlist, under Settings › Security. Rules are individual addresses or ranges in CIDR notation (an address followed by a slash and a prefix length, such as 203.0.113.0/24), IPv4 or IPv6.
- With no rules, the organization is reachable from any network. This is the default.
- With one or more rules, only a connection from a matching address can reach the organization’s signed-in pages and its data. Requests from other addresses are refused, not merely hidden.
- Vintage refuses to save a list that would not include the admin’s own current address, and names the address to add, so an admin cannot lock themselves out.
- Someone connecting from a disallowed address sees a page that explains this and shows their own address, never the allowlist. From there they can switch to another organization they belong to, sign out, or email support.
Accounts and sessions
Section titled “Accounts and sessions”- Email verification is required. A new account confirms its address with a 6-digit code before it can use Vintage. Codes expire after a short window, and wrong attempts are limited.
- Sessions last 60 days and roll forward with use. Someone who keeps working is never asked to sign in again; 60 days without activity ends the session. Signing out ends it at once.
- Sign out of all other devices in Settings › Profile ends every session except the one you are using. The other devices are signed out the next time they are used.
- Resetting a forgotten password ends every other session on the account and signs you in on the device you reset from. The reset link expires after one hour, and the request page never reveals whether an address has an account. Changing your password from Settings does not sign out other devices; use Sign out of all other devices for that.
- Changing your login email needs proof of both mailboxes: a code sent to your current address, then a code sent to the new one. Someone using a signed-in browser cannot move your account to an address of their own, and the code to your current address doubles as a warning.
- When a session ends while Vintage is open, you are returned to the sign-in screen, and after signing in you are taken back to where you were.