Sonsoto handles sensitive identity, company, residency, property, financial, compliance, and family documents. Security is therefore part of the product design: one controlled client profile, one document vault, role-based access, audit history, and limited sharing with the partners and authorities needed for each workflow.
This Security Statement describes the measures Sonsoto uses to protect client files. No online system can be guaranteed to be completely secure, but Sonsoto uses practical technical and organizational controls designed to reduce risk.
Sonsoto is designed to protect data in transit using secure network protocols such as HTTPS/TLS. Uploaded documents and platform data are stored using cloud infrastructure that supports encryption at rest. Where third-party services process data for Sonsoto, we expect appropriate encryption and security controls for the service they provide.
Access to client information is limited based on role, service need, and operational responsibility. Sonsoto team members, agents, partners, and service providers should only access the information required for the workflow they are supporting. Administrative access is restricted and reviewed as part of operational security.
Sonsoto uses passwordless authentication (email magic link, passkey, social sign-in, or national ID) to protect client access — there are no passwords. You are responsible for maintaining control of your email account and devices, keeping any passkeys secure, and notifying Sonsoto if you suspect unauthorized access. We may add or require stronger authentication controls as the platform evolves.
The document vault is designed to centralize sensitive documents so they can be reused responsibly instead of being repeatedly emailed or uploaded across disconnected providers. Vault records include status, expiry, reuse, review, and audit information so Sonsoto can track which documents are on file and what still needs attention.
Documents may be shared outside the vault only when needed for a service, partner handoff, legal obligation, compliance check, authority submission, or client instruction.
Sonsoto may log account activity, document uploads, workflow status changes, partner handoffs, administrative actions, authentication events, errors, and security events. These logs help support accountability, troubleshooting, fraud prevention, compliance, and incident response.
Sonsoto uses cloud, database, storage, communication, payment, analytics, compliance, and support vendors to operate the platform. We aim to select vendors with appropriate security practices for the sensitivity of the service. Vendor access is limited to the purpose for which the vendor is used.
Some workflows require sharing information with external partners, authorities, banks, insurers, brokers, developers, trustees, notaries, professional advisors, or compliance providers. Sonsoto cannot control every external system, portal, mailbox, or partner process, but we aim to share only the relevant information needed for the workflow and to work with appropriate counterparties.
Sonsoto’s operating model is to keep one organized file, not to collect unnecessary data. We ask for information and documents because they are needed for a workflow, compliance check, partner review, authority submission, support request, payment, legal obligation, or platform operation.
If Sonsoto identifies a security incident, we will assess the issue, work to contain it, investigate the cause, take appropriate remedial action, and notify affected users or authorities where required by applicable law. We may ask users to reset credentials, verify account activity, or provide additional information during an investigation.
You can help protect your Sonsoto account by keeping your email account secure, safeguarding any passkeys or devices you use to sign in, avoiding shared devices where possible, checking links before clicking, keeping documents accurate and current, and telling us quickly if something looks wrong. Do not upload files you are not authorized to provide or send sensitive documents over unsecured channels unless Sonsoto specifically instructs you to do so.
If you believe your account, documents, or Sonsoto data may be at risk, contact us immediately at security@sonsoto.com. Please include a clear description of the issue, the affected account or workflow if known, and any relevant timestamps. Do not include unnecessary sensitive documents in the first report.
Off-hours — we reply first thing at 9:00 local. Vy is always on.
We use strictly necessary cookies to run the site. With your consent we'd also use optional cookies (e.g. support tools). You can accept, reject optional, or choose. Cookie policy.