1. Local-First Security Approach
EPM Vitals is designed as a purely local software tool for EPM artifact review.
The product does not require a public cloud account, hosted workspace, remote processing server, or internet connection to process your EPM files after it is installed and activated. Your files are selected and processed in your local environment, and the generated results are written locally.
This matters because EPM review often involves sensitive artifacts: files, grids, metadata packages, application snapshots, mappings, business rules, calculation logic, and review outputs. EPM Vitals is designed so that this review work can happen locally instead of requiring customer artifacts to be uploaded to a vendor-hosted processing service.
2. No Internet Dependency For Product Processing
EPM Vitals product workflows are intended to run without internet dependency.
For normal product use:
- EPM artifact processing runs locally.
- Input files remain in the user's local environment.
- Review outputs are generated locally.
- EPM Vitals does not require a cloud login to run reviews.
- EPM Vitals does not need to upload customer EPM artifacts to Provider servers to perform validation, comparison, conversion, readiness, or impact review workflows.
The public website, email contact, payment flow, product delivery, and support communication are separate from local product processing.
3. Customer Control Of Files And Outputs
Users control which files they open or process with EPM Vitals.
Users also control where generated Outputs are stored, copied, emailed, archived, or deleted. Outputs may include sensitive business information derived from the original Artifacts, so they should be protected under the same internal rules that apply to the original files.
Examples of Outputs that may contain sensitive information include:
- validation result workbooks;
- metadata comparison outputs;
- mapping review outputs;
- application impact or readiness outputs;
- business logic review outputs;
- logs, screenshots, and exported review evidence.
4. Production Data And Bug Debugging
Provider does not accept production customer data directly for ordinary bug debugging.
If you report a product issue, do not send production EPM files, live customer exports, confidential metadata packages, production snapshots, real financial data, or client-sensitive business rules.
Use one of these safer options instead:
- sanitized sample files;
- representative dummy data;
- redacted screenshots;
- redacted error messages;
- a minimal reproduction workbook;
- structure-only examples that remove confidential member names, values, and client identifiers.
If a real production Artifact is ever required for a paid pilot, controlled evaluation, or special support case, it must be handled under a separate written agreement that defines scope, transfer method, access, retention, and deletion.
5. Demo And Evaluation Data
Standard demos should use prepared demo assets or representative examples, not confidential customer production data.
For a personalized evaluation, sanitized or representative Artifacts should be used first. If a prospect believes real data is required to prove fit, the handling rules should be agreed before any file is shared.
6. Activation Data
EPM Vitals uses local activation.
Some machine-bound licenses may require a machine request. The machine request is generated locally and can include:
- product identifier;
- product version;
- request ID;
- generated timestamp;
- optional machine label entered by the user;
- hashed machine fingerprint data.
The machine request does not require customer EPM Artifacts. It should not include production files, metadata packages, grids, snapshots, or business rules.
The user may send the machine request to the EPM Vitals provider to receive a machine-bound activation code. The EPM Vitals application does not need to upload EPM Artifacts for activation.
For the local processing boundary and safe support practices, see the Local Processing And Data Safety guide.
7. Website And Email Contact
The EPM Vitals website and email contact are separate from local product processing.
If you email us, request a demo, request a license, or ask for support, we will receive the contact information and message content you choose to send. Do not include production data or confidential customer files in ordinary email support requests.
If future website features add broader account forms, payment processing, analytics, downloads, or customer portals, a separate privacy notice may be needed to describe those flows.
8. Customer Responsibilities
Customers and users are responsible for:
- deciding which Artifacts may be processed with EPM Vitals;
- ensuring they have permission to process client, employer, or third-party Artifacts;
- securing the local machine where EPM Vitals runs;
- controlling local folder access and file permissions;
- protecting generated Outputs;
- managing backups, retention, deletion, and sharing;
- redacting confidential data before sending support materials;
- following internal security, privacy, audit, and client obligations.
9. What EPM Vitals Does Not Claim
EPM Vitals is designed to reduce unnecessary data transfer by supporting local review workflows, but no software tool can remove all security risk.
Unless separately verified and agreed in writing, EPM Vitals does not claim:
- SOC 2 certification;
- ISO 27001 certification;
- HIPAA compliance;
- PCI compliance;
- guaranteed regulatory compliance;
- guaranteed zero data exposure;
- protection against compromise of the user's own machine, account, network, storage, or file-sharing system.
10. Security Contact
For security, data handling, or support questions, contact:
support@epmvitals.com
Do not attach production data to the first email. Start with a description, redacted screenshot, or sanitized reproduction plan.
Book 20-min demo