Skip to content
VÖRSANN

Security & identity

Know who operates the page.

VÖRSANN operates this website. Google verifies identity when controlled Google Sign-In is enabled; VÖRSANN controls authorization to its own workspaces.

Approved-user WellGuard case access is intentionally paused while VÖRSANN completes security and platform review.

How Google Sign-In works

  1. You begin on a VÖRSANN page at vorsann.store.
  2. Your browser is redirected to Google at accounts.google.com.
  3. Google handles the password, account recovery and any 2FA challenge.
  4. Google returns a limited identity assertion to VÖRSANN.
  5. VÖRSANN checks whether that identity is approved for an organization, program and case.

VÖRSANN does not receive your Google password or 2FA code.

Service relationships

VÖRSANN

Operates the application, approves users and controls workspace permissions.

Google

Acts as the identity provider on Google-controlled pages. Google authentication is not operated by VÖRSANN.

Vercel and Railway

Provide application-hosting and database infrastructure used by VÖRSANN.

Recognize a legitimate flow

  • The VÖRSANN page uses HTTPS on vorsann.store.
  • The Google identity screen uses HTTPS on accounts.google.com.
  • Do not paste or forward callback URLs containing code=, session cookies or tokens.
  • Stop if a page asks you to send a password or 2FA code directly to VÖRSANN.

Security controls

Controlled workspaces use server-side sessions, restricted database credentials, permission checks, audit events, no-store responses and noindex controls. Access may be disabled during security review or maintenance. These controls reduce risk but do not make any internet service risk-free.

Report a concern

Use the contact page or the published security.txt. Include the affected URL and what you observed. Never send live passwords, 2FA codes, OAuth codes, database credentials, access tokens or private evidence.