VITAL Suite Rich in Thought Solutions
VITAL Suite ยท Last updated 2026-04-22

Security

This page summarizes how Rich in Thought LLC protects data in the VITAL Suite dashboard product (the "Service"). A deeper security-posture document is available to prospective customers and vendor reviewers at security@richinthought.com.

1. Data flow

The Service reads financial, payroll, CRM, and marketing-automation data from third-party services (QuickBooks Online, Gusto, HubSpot, ActiveCampaign) via each service's OAuth 2.0 authorization flow. We request read-only scopes and never hold write credentials. Data is pulled on a nightly cadence plus on-demand from the connected user's dashboard.

2. Encryption

3. Tenant isolation

Every customer tenant has its own company_id scope. Isolation is enforced at two layers:

4. Authentication

5. Infrastructure

6. Operational controls

7. Incident response

If we discover a security incident affecting customer data, we notify affected customers within 72 hours (per GDPR Article 33) with the nature of the incident, the data involved, our remediation steps, and the incident-response contact. Report suspected incidents to security@richinthought.com.

8. Responsible disclosure

We welcome security research. If you identify a vulnerability:

We do not currently run a paid bug bounty, but meaningful reports are acknowledged and credited with the reporter's permission.

9. Vendor reviews

For customer security questionnaires, SIG Lite, or CAIQ submissions, request the VITAL Suite Security Posture document at security@richinthought.com. We respond within two business days.