Veteran organizations are being targeted for their databases. This briefing shows exactly how VME's platform defends that data at every layer, in plain terms - and how it holds up against the vendors we use today.
No single wall protects the data. A request has to clear five checkpoints before it can touch a member's record - and each checkpoint is a real, tested control, not a promise.
Four of the protections above, shown in detail - this is the substance behind the posture.
Staff sign in through Microsoft. Members and outside leadership get a one-time code emailed to them - nothing to reuse, phish, or guess.
Everything travels over encrypted connections. Sensitive fields are locked at rest with AES-256-GCM - the same standard Gravyty uses - and the key is kept apart, used only when data is actually needed.
A system independent of the app re-checks all 12 core controls every three hours and raises an alarm the moment one slips. An AI agent also attacks the platform the way a real intruder would.
Every data source is backed up nightly to storage that is locked write-once for 90 days. Even an intruder who gets in cannot delete or tamper with the backups - a bad day stays recoverable.
We asked MembershipWorks and Gravyty directly how they protect your data (July 2026). Their own answers, next to VME.
| Security feature | VMEour platform | MembershipWorks | Gravyty |
|---|
The honest read: VME matches the technical protections of both vendors, and re-tests its defenses every few hours where they test quarterly or once a year. The one thing Gravyty has that VME doesn't yet is the independent SOC 2 seal - which VME is now pursuing.
SOC 2 is a formal audit where an outside firm confirms, with months of evidence, that VME does what it says. Gravyty holds it; VME is pursuing it - the full set, not the usual one.
A SOC 2 Type II audit typically takes about 6 to 12 months and costs roughly $20,000 to $50,000 in the first year, between the independent auditor and the compliance tooling. VME is on that path now.