Security
Your application holds some of the most sensitive documents you own. VisaOS prepares your application automatically — your documents are held in private storage, encrypted at rest and in transit, and read by software so a pack can be built from them. No one at VisaOS reviews, checks or opens what they contain.
1 · What protects your documents
- PRIVATE STORAGE
- Your documents are held in private storage. No document is published, none is given a public address, and nothing is readable by anyone who happens to have a link. Every read is a short-lived link issued to your own session.
- AES-256 AT REST
- Stored documents and records are encrypted at rest with
AES-256by the infrastructure VisaOS runs on. This is the provider’s cryptography, correctly attributed — VisaOS does not implement its own. - TLS IN TRANSIT
- All traffic between your browser and VisaOS travels over
HTTPSusing currentTLS, as does traffic between VisaOS and its database and storage. The first half of that is verifiable from your own browser, which is why we state it without qualification. - ACCESS CONTROLS
- Your application and its documents are held against your account and are not pooled across accounts. Ownership is enforced at the database with per-owner policies, and re-checked on the server for every request.
We name encryption in transit and encryption at rest separately, and never collapse the two into one undifferentiated “encrypted”. They are different protections covering different moments in a document’s life, and a reader is entitled to know which one is being claimed. Section 2 sets out the part that neither of them covers: who actually sees what your documents contain.
2 · Who sees your documents
This is the part most services leave vague, so it is the part we are most specific about. VisaOS prepares your application automatically, and no one here reviews, checks or opens the contents of your documents. There is no internal viewer, no review queue and no approval step that a person at VisaOS performs on your passport or your bank statements.
Three parties are involved with your documents, and it is worth naming each one exactly.
- 01Our software. VisaOS builds your application pack, so its systems necessarily read your files — they open PDFs, turn pages into images and assemble the document you review. This is automated processing, and we state it plainly rather than let “no human review” be read as “nothing reads it”.
- 02You. The judgement is yours. VisaOS shows you every section and every document that went into your pack so you can read the whole thing before it goes anywhere, and nothing is submitted on your behalf.
- 03The Embassy or Consulate. They see your application and your documents when you choose to export and submit them. That is the point of the exercise, and it happens at your instruction, not ours.
Prepared by software. Not reviewed by people.
Human support is real: a person reads what you write to help@visa-os.com. Answering you does not involve opening your documents — support works from your account and your application status, never from your files.
To be exact about where the boundary falls: our systems process your documents, because that is how a pack gets built — VisaOS’s own servers read your evidence. People at VisaOS do not: nobody here inspects, checks or reviews what your documents contain. That is what this page claims, and it is deliberately narrower than what a security page is tempted to claim — the protection is against people, and we say which one we mean.
3 · How a document moves through VisaOS
- 01 · UPLOAD
- Your file leaves your browser over an encrypted connection and goes directly to storage.
- 02 · STORE
- It lands in private storage, held against your application and reachable only from your account.
- 03 · PROTECT
- It is encrypted at rest with
AES-256by the infrastructure VisaOS runs on. - 04 · PREPARE
- Software reads it and builds your application pack from it. No VisaOS person reviews, checks or opens what it contains.
- 05 · REVIEW
- You read the finished pack, and you decide when to export it and submit it to your Embassy or Consulate.
Deleting your application removes the documents inside it. Export anything you want to keep before you do — deletion cannot be undone and VisaOS cannot recover it for you. See section 5.
4 · The infrastructure underneath
VisaOS handles serious personal documents, so it is built on serious infrastructure. That choice is deliberate and it is part of the protection, not an implementation detail.
- SUPABASE
- Database and private document storage. Supabase holds
SOC 2andISO 27001certification, and provides theAES-256encryption at rest described in section 1. - VERCEL
- Application and website hosting, and
TLStermination. Vercel holdsSOC 2andISO 27001certification.
Those certifications belong to those providers. VisaOS itself holds no SOC 2 or ISO certification and does not claim one — borrowing a provider’s certificate would be exactly the kind of invented certainty this site refuses everywhere else. Both providers are listed with their role and processing detail on Companies that help provide VisaOS.
5 · Your account and your data
- SIGNING IN
- You sign in with an email address and a password you control. Sign-in attempts are rate-limited and session tokens expire. Multi-factor authentication is not available — we would rather tell you that than let you assume it.
- EXPORT AND DELETION
- Export is how you take a copy of your application, and deletion is how you remove it. Those are the two things VisaOS gives you, so export anything you want to keep before you delete an application — there is no separate recovery route afterwards.
- DELETION
- Deleting an application removes the documents inside it rather than hiding them from view. Removal from active systems within 30 days, and expiry of residual encrypted backup copies within 90 days, are the commitments set out in the Privacy Notice. We have not published an independent verification that deletion propagates to every store and every backup.
- YOUR PRIVACY RIGHTS
- Your statutory rights are separate from what the product has a button for. Access, correction, erasure, portability and the rest are described in the Privacy Notice, and are exercised by writing to the privacy contact — not by a self-service control we have not built.
- ENVIRONMENT SEPARATION
- Development and testing environments are intended to be fully separate from production, and never to contain real applicant documents. We state that as our design rather than as an audited fact: no independent verification of that separation has been carried out.
6 · Operational transparency
The controls above are built and enforced in the product. The operational practices around them are at different stages, and each row below says what exists and what does not, rather than letting the confident half of the page speak for the rest.
- MONITORING
- Security and error logging exists so that failures and suspicious activity can be investigated, and security logs are kept for the 12 months set out in the retention schedule. We do not operate defined alerting thresholds or on-call coverage, and we would rather say so than let you assume a response capability we do not have.
- BACKUPS
- Backups exist so that a failure does not cost you your application. We have not published their frequency, their encryption, where they are held, or — importantly — the result of a restoration test. An untested backup is a hope, not a control, and we will publish a test result rather than an intention.
- INCIDENT RESPONSE
- If a security incident affects your information, our commitment is to investigate, contain it, tell you what happened and what we are doing, and notify the relevant supervisory authority where the law requires it. We do not publish severity definitions or notification timings, because we are not going to make a response-time promise we cannot keep.
- SUPPLIER REVIEW
- Every provider with access to applicant information is reviewed before use and reassessed periodically, with a written processing agreement in place. The register is on Companies that help provide VisaOS, which names the providers we have published and says plainly where one is not named.
7 · Your part
- Use a password you have not used anywhere else.
- Keep access to your email secure — it can reset your account.
- Sign out on shared or public computers.
- Export a copy of anything you want to keep before you delete an application.
- Delete applications you no longer need.
- Tell us immediately at help@visa-os.com if you think someone else has reached your account.
8 · Responsible disclosure
If you have found a weakness, we want to hear from you before anyone else does, and we will not pursue anyone who reports in good faith. See Report a security issue.
Private from people. Protected by world-class infrastructure.
Every control on this page is one we can point at in the running product. Where a practice is an intention rather than a finished control, the sentence describing it says so in its own words — we would rather show you which is which than present a page where everything reads equally certain.