Security at Vendeflect, stated plainly.
We help teams answer security reviews, so we will not hand-wave our own. Here is what is true today, and what is not yet.
How your data is handled.
Encrypted in transit and at rest
Traffic is served over TLS, and stored data is encrypted at rest by the managed database and object storage we run on.
Your team approves every answer
The product is built so an AI draft cannot be sent on its own. A person on your side approves the final answer.
Your documents stay yours
Your uploaded documents are used to answer your questionnaires. We do not use them to train models for other customers.
Least privilege access
Access to production is limited and logged. We scope credentials to what a task needs rather than granting standing access.
What we do not claim yet.
Vendeflect is early. We do not hold a SOC 2 report, we are not ISO 27001 certified, and we have not completed a third party audit. We would rather tell you that than point at a badge we have not earned. As that posture changes, this page changes with it, and any report will be available here under NDA.
If you are evaluating us and need something specific for your own review, ask. We answer security questions the same way we ask our customers to: from the actual state of the system.