← Back to VRS One

Trust & Compliance

Last updated: 2026-05-28 · Questions: security@vrsjo.com

Security architecture

VRS One is a single Cloudflare Workers application deployed at app.vrsjo.com. Every request is served over HTTPS; HTTP-only traffic is rejected at the edge. The application stack:

Identity & access

Multi-tenant isolation

AI safety & compliance

Network — for customer IT teams

To allowlist VRS One in an egress firewall: our customer-facing domain is app.vrsjo.com. Production traffic is served via Cloudflare Workers — the official Cloudflare IP ranges (cloudflare.com/ips) cover every region. Outbound webhooks from VRS One (planned) will originate from the same Cloudflare ranges. Please reach out via security@vrsjo.com if you need a tenant-scoped IP allowlist on inbound requests.

Data privacy & residency

Operational controls

Compliance frameworks

Incident & breach response

Reporting a vulnerability

We welcome responsible disclosures. Email security@vrsjo.com; we acknowledge within 2 business days. Please don't run automated scanners against production — use a sandbox engagement instead, we can provision one on request.