Very Good Security

Very Good Security (VGS) is a data security and payments infrastructure company that lets organizations operate on sensitive data — payment card numbers, bank accounts, PII, and other regulated information — without the cost or liability of storing it themselves. Its core Vault tokenization platform substitutes sensitive values with format-preserving aliases so customer systems never touch raw data, dramatically reducing PCI DSS, SOC 2, HIPAA, and GDPR compliance scope. VGS also offers Zero Data (a proxy that keeps the customer environment entirely out of PCI scope), a Card Management Platform (network tokens, account updater, 3D Secure), and VGS Control for compliance automation. The developer surface includes the Vault HTTP API for aliases/tokenization, VGS Collect and VGS Show client SDKs, a Terraform provider, and the vgs-cli command line tool. Founded in 2015, VGS is backed by a16z and stores over 5 billion tokens.

Very Good Security publishes 1 API on the APIs.io network: aliases API. Tagged areas include Company, Data Security, Tokenization, Payments, and Vault.

The Very Good Security catalog on APIs.io includes 1 event-driven AsyncAPI specification.

Very Good Security’s developer surface includes CLI, sandbox, changelog, authentication, documentation, API reference, getting-started guide, and 30 more developer resources.

65.6/100 strong ▬ flat Agent 61/100 agent native Full breakdown ↓
scored 2026-07-23 · rubric v0.5
AccessSelf serve
1 APIs 1 MCP Servers
CompanyData SecurityTokenizationPaymentsVaultPCI ComplianceData PrivacyCard ManagementNetwork TokensSecurity

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-23 · rubric v0.5
Composite quality — 65.6/100 · strong
Contract Quality 17.3 / 25
Developer Ergonomics 17.4 / 20
Commercial Clarity 12.1 / 20
Operational Transparency 5.8 / 13
Governance 0.0 / 12
Discoverability 9.3 / 10
Agent readiness — 61/100 · agent native
Machine-Readable Contract 18 / 18
Agentic Access Contract 0 / 15
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 6 / 6
Agent Skills 5 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/very-good-security: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

Very Good Security aliases API

Unique IDs that retain all the essential information about the data without compromising its security.

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Very Good Security Authentication

http/oauth2 · 2 schemes

SECURITY

Very Good Security Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Very Good Security Trust Center

SOC 2, ISO 27001, PCI DSS, GDPR

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Very Good Security Scopes

3 scopes · clientCredentials

3 scopes

SCOPES

Resources

Get Started 5

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 4

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 7

Pagination, idempotency, versioning, errors, and events

Scroll for all 7

Build 4

SDKs, sample code, and the tooling you integrate with

Access & Security 6

Authentication, authorization, and security posture

Operate 4

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 1

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: very-good-security
name: Very Good Security
description: Very Good Security (VGS) is a data security and payments infrastructure company that lets organizations operate
  on sensitive data — payment card numbers, bank accounts, PII, and other regulated information — without the cost or liability
  of storing it themselves. Its core Vault tokenization platform substitutes sensitive values with format-preserving aliases
  so customer systems never touch raw data, dramatically reducing PCI DSS, SOC 2, HIPAA, and GDPR compliance scope. VGS also
  offers Zero Data (a proxy that keeps the customer environment entirely out of PCI scope), a Card Management Platform (network
  tokens, account updater, 3D Secure), and VGS Control for compliance automation. The developer surface includes the Vault
  HTTP API for aliases/tokenization, VGS Collect and VGS Show client SDKs, a Terraform provider, and the vgs-cli command line
  tool. Founded in 2015, VGS is backed by a16z and stores over 5 billion tokens.
url: https://raw.githubusercontent.com/api-evangelist/very-good-security/refs/heads/main/apis.yml
x-type: company
x-source: vc-portfolio
x-backed-by:
- a16z
x-tier: profiled
x-tier-reason: enriched-from-live-surface
accessModel:
  pricing: unknown
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Self-serve signup
  confidence: medium
  source:
  - authentication
  generated: '2026-07-22'
  method: derived
specificationVersion: '0.20'
image: https://www.verygoodsecurity.com/favicon.ico
created: '2026-07-17'
modified: '2026-07-21'
x-enrichment:
  date: '2026-07-21'
  status: enriched
  artifacts_added: 19
  pass: local-v1
tags:
- Company
- Data Security
- Tokenization
- Payments
- Vault
- PCI Compliance
- Data Privacy
- Card Management
- Network Tokens
- Security
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
apis:
- aid: very-good-security:very-good-security-aliases-api
  name: Very Good Security aliases API
  description: 'Unique IDs that retain all the essential information about the data

    without compromising its security.'
  humanURL: https://www.verygoodsecurity.com/docs/vault/api/
  baseURL: https://api.live.verygoodvault.com
  tags:
  - aliases
  properties:
  - type: OpenAPI
    url: openapi/very-good-security-aliases-api-openapi.yml
  - type: APIReference
    url: https://www.verygoodsecurity.com/docs/vault/api/
  - type: Documentation
    url: https://docs.verygoodsecurity.com/vault/developer-tools/apis/vault-api
common:
- type: Packages
  url: packages/very-good-security-packages.yml
- type: SDKs
  url: packages/very-good-security-packages.yml
- type: WellKnown
  url: well-known/very-good-security-well-known.yml
- type: MCPServer
  url: mcp/very-good-security-mcp.yml
- type: LLMsTxt
  url: llms/very-good-security-llms.txt
- type: Overlay
  url: overlays/very-good-security-vault-overlay.yaml
- type: Conformance
  url: conformance/very-good-security-conformance.yml
- type: ErrorCatalog
  url: errors/very-good-security-problem-types.yml
- type: Lifecycle
  url: lifecycle/very-good-security-lifecycle.yml
- type: OAuthScopes
  url: scopes/very-good-security-scopes.yml
- type: CLI
  url: cli/very-good-security-cli.yml
- type: Sandbox
  url: sandbox/very-good-security-sandbox.yml
- type: Conventions
  url: conventions/very-good-security-conventions.yml
- type: ChangeLog
  url: changelog/very-good-security-changelog.yml
- type: Components
  url: components/very-good-security-components.yml
- type: DataModel
  url: data-model/very-good-security-data-model.yml
- type: Webhooks
  url: asyncapi/very-good-security-webhooks.yml
- type: AgentSkill
  url: skills/_index.yml
- type: TrustCenter
  url: security/very-good-security-trust-center.yml
- type: DomainSecurity
  url: security/very-good-security-domain-security.yml
- type: Authentication
  url: authentication/very-good-security-authentication.yml
- type: DeveloperPortal
  url: https://docs.verygoodsecurity.com/
- type: Documentation
  url: https://docs.verygoodsecurity.com/
- type: APIReference
  url: https://www.verygoodsecurity.com/docs/vault/api/
- type: GettingStarted
  url: https://www.verygoodsecurity.com/docs/tokenization/getting-started
- type: Blog
  url: https://www.verygoodsecurity.com/blog/
- type: GitHubOrganization
  url: https://github.com/verygoodsecurity
- type: Support
  url: mailto:support@verygoodsecurity.com
- type: SignUp
  url: https://dashboard.verygoodsecurity.com/tokenization
- type: Login
  url: https://dashboard.verygoodsecurity.com
- type: Pricing
  url: https://www.verygoodsecurity.com/pricing
- type: TermsOfService
  url: https://www.verygoodsecurity.com/terms-and-conditions
- type: PrivacyPolicy
  url: https://www.verygoodsecurity.com/privacy-notice
- type: StatusPage
  url: https://status.verygoodsecurity.com/
- type: TrustCenter
  url: https://security.verygoodsecurity.com/
- type: Compliance
  url: https://security.verygoodsecurity.com/
- type: ChangeLog
  url: https://docs.verygoodsecurity.com/overview/release-notes