Security & Trust
Venari helps people make decisions involving real money.
That makes trustworthy data handling, explainable recommendations, and controlled system behavior part of the product—not an afterthought.
Venari is operated by The Viral Marketer, LLC.
Privacy by Design
We aim to collect only information reasonably needed to operate, improve, protect, and lawfully market Venari.
Our engineering approach emphasizes:
- minimizing sensitive-data collection and exposure;
- validating untrusted inputs;
- preserving provenance for consequential decisions;
- keeping deterministic authority where deterministic rules are appropriate; and
- keeping high-authority actions under explicit control.
Examples include:
- Venari does not require your Facebook password for browser-assisted analysis;
- the browser-assisted Marketplace workflow is user-controlled;
- raw Value My Stuff photos are not permanently stored by Venari under the current architecture;
- optional advertising tracking is separated from private resale workflows; and
- customer outcome information used for long-term Market Intelligence should be de-identified before surviving account deletion.
Two Marketplace Workflows
Venari has two distinct Marketplace workflows.
Browser-Assisted Analysis
For authenticated browser-assisted Facebook use:
you navigate Facebook and explicitly present the evidence you want Venari to analyze.
Venari does not need your Facebook password or authentication cookies for that workflow.
The audited extension architecture is designed around explicit user action rather than hidden Marketplace navigation.
Saved Search Monitoring
Saved Search Monitoring is separate.
A customer configures a search and Venari may use an approved external marketplace-data/source provider to obtain relevant marketplace observations.
Monitoring does not require Venari to take control of the customer's authenticated Facebook account or session.
The external provider must pass applicable legal, privacy, contractual, and data-rights review before normal production use.
Account Security
Venari includes account controls such as:
- password hashing;
- email verification;
- password-reset flows;
- authenticated sessions;
- session expiration/revocation;
- account-status controls; and
- administrative audit records.
We design authentication and administrative access around the minimum authority necessary for the applicable operation.
Payment Security
Payments are handled through a specialized payment provider such as Stripe.
Venari does not require its own application database to store your full payment-card number.
AI and Data Providers
Some Venari features use external providers for AI processing, email, hosting, payments, or marketplace observations.
We treat external providers as trust boundaries.
Our engineering standards require bounded inputs, validation, explicit provider authority, provenance, safe failure, resource/cost limits, and separation between probabilistic AI advice and authoritative deterministic rules.
Venari does not allow generative AI to silently become authority for financial calculations that should be deterministic.
Value My Stuff Photos
When you use Value My Stuff, photographs may be temporarily processed and transmitted to an approved AI service provider to perform the requested analysis.
Under the current Venari architecture:
raw Value My Stuff photos are not permanently stored in Venari Inventory or retained as permanent Venari photo files.
Limited provenance such as image dimensions or cryptographic digest information may be retained with the analysis.
Acquisition Decision Safety
An acquisition recommendation can influence whether someone spends real money.
Venari therefore separates:
- seller claims;
- visible evidence;
- market evidence;
- AI/model observations; and
- deterministic financial calculations.
Important financial calculations are designed to be reproducible from their authoritative inputs.
Provider-Spend Controls
External provider operations can cost money and may have irreversible external effects.
Venari uses explicit authorization boundaries around sensitive paid-provider operations.
Engineering verification should use offline evidence or mocks unless real external use is deliberately authorized.
This reduces accidental duplicate provider spending and prevents uncertain external results from triggering blind retries.
Data and Evidence Provenance
Where decisions matter, Venari aims to retain enough provenance to understand:
- where information came from;
- which evidence supported a conclusion;
- when information was observed;
- which analysis/rule version applied;
- which provider was involved where relevant; and
- which deterministic inputs produced important financial outputs.
This helps investigate mistakes and improve the product without pretending probabilistic outputs are certain.
Advertising Isolation
Our advertising architecture is separated from the private resale product.
Optional advertising technologies may operate in the public acquisition funnel, such as:
public website
→ signup
→ trial activation
→ subscription conversion
Advertising pixels and audience tracking are not intended to operate inside private workflows such as:
- Acquisition Inbox;
- Saved Searches;
- Inventory;
- Marketplace analysis;
- Deep Analysis;
- Value My Stuff results; or
- private customer economics.
Private resale information such as Saved Search terms, Buy Under values, acquisition prices, sale prices, Inventory, or VMS photos is not intended to be ordinary advertising-event data.
Administrative Access
Company personnel should access customer information only where there is a legitimate operational reason, such as:
- customer support requested by the customer;
- privacy-request handling;
- security or abuse investigation;
- controlled debugging; or
- legal compliance.
Administrative functionality/access should be limited according to role and need.
Internal/admin notes, if implemented, must not become customer-accessible merely because they exist in the same system.
Privacy Requests and Deletion
Customers may contact:
privacy@theviralmarketer.com
to request access, correction, deletion, or withdrawal of optional privacy choices.
Our general operational target is to complete a verified ordinary privacy request within 30 days, subject to applicable exceptions.
Account deletion and subscription cancellation are separate actions.
Eligible market outcome information may survive deletion only after appropriate de-identification or aggregation.
Service Providers
We use third-party providers for functions such as cloud hosting, payments, transactional email, AI processing, and marketplace/source observations.
Material production providers are documented separately on our Subprocessors & Third-Party Services page after production verification.
We review a provider's role before representing it as a Venari subprocessor.
Backups and Recovery
Venari engineering includes database backup and restore tooling.
Production backup schedules, retention periods, and offsite arrangements are operational controls rather than marketing promises until verified.
We do not currently publish a contractual recovery-time or recovery-point guarantee.
Deleted information may remain temporarily in backups until those backups expire under the applicable backup lifecycle.
Service Availability
Venari does not currently offer a general contractual uptime SLA.
The service can depend on external systems such as cloud infrastructure, payment providers, email providers, AI providers, marketplace-data providers, and third-party marketplaces.
A dependency failure should have a bounded and understandable effect rather than silently producing false success.
Security Incidents
No internet-connected service can guarantee that a security incident will never occur.
If we become aware of a security or privacy incident, our policy is to:
- investigate;
- contain the issue where possible;
- preserve relevant evidence;
- determine affected information/users;
- remediate the underlying problem; and
- provide legally required notifications.
We do not use claims such as “100% secure” or “impossible to breach.”
Responsible Security Reports
If you believe you have discovered a security issue involving Venari, contact:
security@theviralmarketer.com
Please do not:
- access another person's account/data;
- disrupt the service;
- destroy or alter information;
- use social engineering;
- attempt credential theft;
- perform denial-of-service activity;
- interact with marketplace accounts you do not own; or
- retain unnecessary copies of customer information.
We ask that reports include enough detail for us to understand and reproduce the issue.
No public bug-bounty payment program is currently promised.
SOC 2
Approved wording:
We are developing controls, policies, and evidence practices that may support a future SOC 2 examination if and when the company formally scopes and pursues one.
Venari does not currently claim:
- SOC 2 certification;
- SOC 2 compliance;
- SOC 2 Type I;
- SOC 2 Type II; or
- an auditor-issued SOC 2 report.
If we complete an independent examination in the future, we will update this page accurately.
SOC 1
Venari does not currently claim a SOC 1 report.
Based on the present product model, SOC 2 is the more relevant initial trust framework.
SOC 1 applicability will be revisited if Venari eventually performs services materially relevant to enterprise customers' internal controls over financial reporting.
Security Contact
Security issues:
security@theviralmarketer.com
Privacy matters:
privacy@theviralmarketer.com
General support:
support@theviralmarketer.com
Venari is operated by:
The Viral Marketer, LLC 1321 Upland Dr, Unit 1713 Houston, Texas 77043 United States