Trust

Security & how we handle files

Visa Engine stores case files so you and your firm can prepare a petition or visitor checklist. This page restates how that works. It is not a certification badge, and it does not replace the Privacy Policy.

What we store

Depending on how you use the product, that can include account data from Google sign-in, case metadata (visa type, scores, notes), uploaded evidence files, preparation answers, drafts, and billing identifiers for paid plans. Upload only materials you are authorized to share with cloud processors.

How access works

Signed-in users reach their own cases. Firm cases use organization roles so attorneys, staff, and invited clients share one file. We use access controls appropriate to a cloud SaaS product. Protected routes still require authentication.

Transport and infrastructure

We use encrypted transport, access controls, and storage on reputable infrastructure providers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Who processes data

We use subprocessors to run the service — not to sell personal information:

  • Supabase — authentication (including Google OAuth), database, and file storage
  • Google — OAuth sign-in
  • OpenAI / AI providers — extraction, analysis, drafting, and chat (via the Vercel AI SDK). We configure providers so submitted content is not used to train their general models, to the extent those terms are available to us.
  • Vercel — hosting, deployments, and related infrastructure
  • Stripe — subscription payments and the billing portal
  • PostHog (EU Cloud) — product analytics, error tracking, and session replay on public marketing pages only. Case documents and in-app evidence screens are not recorded.

Retention and deletion

We keep personal information while your account is active and as needed to provide the service. You can request deletion; we verify the request and delete or de-identify account data except where we must retain limited information for legal, security, or billing records.

If something goes wrong

If we become aware of a personal data breach affecting your information, we will notify you and relevant authorities where required by applicable law.

What we do not claim

We do not claim SOC 2, ISO 27001, or similar certifications on this page. We do not describe Visa Engine as bank-grade or attorney-grade security. For the binding privacy notice, read the Privacy Policy.

Last reviewed: August 16, 2026. This page summarizes facts already in the Privacy Policy.