How VME protects
the data our members trust us with

Veteran organizations are being targeted for their databases. This briefing shows exactly how VME's platform defends that data at every layer, in plain terms - and how it holds up against the vendors we use today.

255
Security checks run
0
Critical issues
12/12
Controls verified live
3h
Re-tested every
Defense in depth

An attacker has to beat every layer

No single wall protects the data. A request has to clear five checkpoints before it can touch a member's record - and each checkpoint is a real, tested control, not a promise.

THREAT unknown request 01 PERIMETER HTTPS / TLS rate-limited 02 IDENTITY Microsoft or one-time email code 03 ACCESS role-checked; your record only 04 ENCRYPTION AES-256 at rest key held apart MEMBER DATA the protected core
Every checkpoint is verified live every 3 hours. Diagram illustrates VME's real controls.
How it actually works

The mechanisms, in plain terms

Four of the protections above, shown in detail - this is the substance behind the posture.

Signing in

No shared passwords to steal

Staff Member Microsoft sign-in One-time codeemailed, 15-min INverified

Staff sign in through Microsoft. Members and outside leadership get a one-time code emailed to them - nothing to reuse, phish, or guess.

Passwordless for members; sessions can be revoked instantly
Protecting the record

Encrypted in transit and at rest

IN TRANSIT browser TLS VME AT REST record AES-256-GCMlocked key held separatelyused only at read-time

Everything travels over encrypted connections. Sensitive fields are locked at rest with AES-256-GCM - the same standard Gravyty uses - and the key is kept apart, used only when data is actually needed.

Same at-rest standard as VME's enterprise vendor
Proving it, continuously

Re-tested every 3 hours

SCAN VERIFY 12controls ALARMif any slip repeat every 3 hours

A system independent of the app re-checks all 12 core controls every three hours and raises an alarm the moment one slips. An AI agent also attacks the platform the way a real intruder would.

Vendors test quarterly or once a year - VME, ~2,900 times
If the worst happens

Backups nothing can erase

4 datasources nightly WRITE-ONCE90-day lock intrudercan't alter

Every data source is backed up nightly to storage that is locked write-once for 90 days. Even an intruder who gets in cannot delete or tamper with the backups - a bad day stays recoverable.

Immutable, off-site, freshness-checked daily
How VME compares

Measured against the vendors we pay today

We asked MembershipWorks and Gravyty directly how they protect your data (July 2026). Their own answers, next to VME.

Security featureVMEour platformMembershipWorksGravyty
✓ Has it Partial / in progress / not confirmed✗ Doesn't have it
And how often is it all tested for weaknesses?
VMEEvery 3 hours
MembershipWorksQuarterly
GravytyOnce a year

The honest read: VME matches the technical protections of both vendors, and re-tests its defenses every few hours where they test quarterly or once a year. The one thing Gravyty has that VME doesn't yet is the independent SOC 2 seal - which VME is now pursuing.

Independent certification

SOC 2 - pursuing all five criteria

SOC 2 is a formal audit where an outside firm confirms, with months of evidence, that VME does what it says. Gravyty holds it; VME is pursuing it - the full set, not the usual one.

A SOC 2 Type II audit typically takes about 6 to 12 months and costs roughly $20,000 to $50,000 in the first year, between the independent auditor and the compliance tooling. VME is on that path now.