Vector GFX Customer Trust & Security Policy

Vector GFX Customer Trust & Security Policy

Vector GFX Customer Trust & Security Policy 

Last Updated: February 20, 2026 


Overview 


At Vector GFX, we understand that our technical illustration software—including canvasxdraw—is a mission-critical tool for your engineering and design workflows. This document outlines our commitment to cyber defense, how we manage vulnerabilities across modern and legacy codebases, and our protocols for responding to security incidents. 


Cyber Defense Program 

Our Cyber Defense Program (CDP) is built on three pillars: Prevention, Detection, and Response. We align our internal practices with the National Institute of Standards and Technology (NIST) Cybersecurity Framework to ensure the integrity and availability of our software. 


1. Vulnerability Management 


We employ a risk-based approach to identifying and remediating flaws in our desktop applications. 

  • Continuous Scanning: We perform regular Static Analysis (SAST) on our core source code and Dynamic Analysis (DAST) on our distribution environments. 

  • Third-Party Dependencies: We monitor a Software Bill of Materials (SBOM) for all third-party libraries used in canvasxdraw and canvasxgeo. 

  • The N-1 Support ModelCurrent Version (N): Receives full security maintenance, including patches for Critical, High, and Medium vulnerabilities. 

  • Preceding Version (N-1): Receives maintenance for Critical security vulnerabilities only. 

  • Legacy (EOL): Software older than N-1 is considered End-of-Life. We do not perform security testing or issue patches for EOL versions. 


2. Secure Engineering Policies 


Security is integrated into our Software Development Lifecycle (SDLC): 


  • Code Signing: All production installers (.exe and .dmg) are digitally signed to ensure authenticity and prevent tampering. 

  • Access Control: Access to our master source code repositories is restricted via Multi-Factor Authentication (MFA) and the Principle of Least Privilege. 

  • Beta Security Integrity: Participants in our Customer-Tested Beta Programoperate in a logically isolated environment. Security findings in Beta builds are treated with "Priority-One" triage to ensure fixes are implemented before stable release. 


Security Disclosure Program (SDP) 


We maintain a "Safe Harbor" for security researchers and customers who discover potential vulnerabilities. 


  • Reporting Channel: Please report all security concerns to support@vectorgfx.net. 

  • SLA for Vulnerability Response: 

  • Triage: We acknowledge critical reports within 24 business hours. 

  • Remediation: Our target for releasing a "Critical" patch is 30 days from verification. 


  • Public Disclosure: We ask that reporters provide us a reasonable time to patch before making any information public. 


Incident Response Plan 


In the event of a verified security breach or the discovery of a "Zero-Day" exploit affecting our users, Vector GFX follows a formal Incident Response (IR) protocol: 


  1. Detection & Analysis: Our IR team verifies the scope of the threat (e.g., a compromised update server or a malicious file-type exploit). 

  1. Containment: We take immediate steps to halt the spread, which may include temporarily disabling download links or revoking compromised digital certificates. 

  1. Customer Notification: If customer data or system security is at risk, Vector GFX commits to notifying affected customers via our Security Advisory mailing list within 72 hours of incident verification. 

  1. Recovery: We provide a "Clean Path" for customers, typically through an out-of-band security update or documented mitigation steps. 


Customer Responsibilities 


To maintain a secure environment, we recommend that customers: 


  • Stay Current: Upgrade to the latest version (N) to receive the most robust security protections. 

  • Verify Signatures: Always verify that the Vector GFX installer is digitally signed by Vector GFX, Inc. before installation. 

  • Isolate Legacy Systems: If your workflow requires the use of EOL (End-of-Life) software, we recommend running those applications in an air-gapped or restricted network environment. 


Proof of Compliance 


For organizations requiring technical proof of these programs, Vector GFX provides: 


  • A machine-readable security.txt file at vectorgfx.net/.well-known/security.txt. 

  • A historical Security Advisory Log within our Knowledge Base. 

  • Annual Security Attestation documents (available upon request for Enterprise customers). 

    • Recent Articles

    • Privacy at a Glance: Vector GFX Data Handling

      Privacy at a Glance: Vector GFX Data Handling Feature Standard License Air-Gapped License Who can see your files? Only You. Vector GFX has zero access to your drawings or IP. Only You. Vector GFX has zero access to your drawings or IP. What user info ...
    • Vector GFX Support Policy Summary

      Vector GFX Support Policy Summary: Stay Current! To ensure you are running the most secure, stable, and feature-rich version of Vector GFX, we maintain a clear N-1 Support Model. This means we focus our resources on supporting the latest technology, ...
    • Security and Trust: Frequently Asked Questions (FAQ)

      Frequently Asked Questions (FAQ): Security & Trust 1. CMMC & Government Compliance Does Vector GFX comply with CMMC 2.0 requirements? Yes. Vector GFX aligns its internal operations and secure development lifecycle with NIST SP 800-171, the foundation ...
    • Security and Trust: Frequently Asked Questions (FAQ)

      Frequently Asked Questions (FAQ): Security & Trust 1. CMMC & Government Compliance Does Vector GFX comply with CMMC 2.0 requirements? Yes. Vector GFX aligns its internal operations and secure development lifecycle with NIST SP 800-171, the foundation ...
    • Vector GFX Customer Trust & Security Policy

      Vector GFX Customer Trust & Security Policy Last Updated: February 20, 2026 Overview At Vector GFX, we understand that our technical illustration software—including canvasxdraw—is a mission-critical tool for your engineering and design workflows. ...
    • Related Articles

    • Vector GFX Customer Trust & Security Policy

      Vector GFX Customer Trust & Security Policy Last Updated: February 20, 2026 Overview At Vector GFX, we understand that our technical illustration software—including canvasxdraw—is a mission-critical tool for your engineering and design workflows. ...
    • Security and Trust: Frequently Asked Questions (FAQ)

      Frequently Asked Questions (FAQ): Security & Trust 1. CMMC & Government Compliance Does Vector GFX comply with CMMC 2.0 requirements? Yes. Vector GFX aligns its internal operations and secure development lifecycle with NIST SP 800-171, the foundation ...
    • Frequently Asked Questions (FAQ): Security & Trust

      Frequently Asked Questions (FAQ): Security & Trust 1. CMMC & Government Compliance Does Vector GFX comply with CMMC 2.0 requirements?  Yes. Vector GFX aligns its internal operations and secure development lifecycle with NIST SP 800-171, the ...
    • Security and Trust: Frequently Asked Questions (FAQ)

      Frequently Asked Questions (FAQ): Security & Trust 1. CMMC & Government Compliance Does Vector GFX comply with CMMC 2.0 requirements? Yes. Vector GFX aligns its internal operations and secure development lifecycle with NIST SP 800-171, the foundation ...
    • Vector GFX Privacy Policy

      Effective Date: October 10, 2025 Last Updated: February 25, 2026 We are committed to protecting your privacy and the security of the information you provide to us. Vector GFX, Inc. (“Vector GFX”) will not sell, rent, lease, or disclose customer ...
    • Popular Articles

    • Exciting Users for Mac Users!

      Exciting news for Mac users! The first universal native app is in developemt! This new version will be compatable with all macOS versions and chipsets. We expect to release in March of 2026. More to come, stay tuned for updates!! - Vector GFX Team
    • Welcome to Vector GFX!

      Please bear with us as we are busy updating all of our help content. If you need immeadiate assistance submit a ticket at https://vgfxsupport.zohodesk.com/portal/en/newticket or e-mail info@vectorgfx.net. Other important links: New Website: ...
    • Vector GFX: Quality Assurance Program Overview

      Vector GFX: Quality Assurance Program Overview At Vector GFX, we are committed to delivering high-performance, stable desktop solutions. Because our software resides directly on our customers' local environments, our Quality Assurance (QA) program ...
    • How many computers can I put a license on?

      Overview: Each license can only be used to register the program on two computers. If you are looking to get more than one license, we can offer a discount for multiple licenses. Please contact our sales department at sales@vectorgfx.net. Applies To: ...
    • What is the difference between Canvas X Draw and Canvas X Pro (Canvas GFX)?