Trust center

Security, privacy, and AI governance

Vectyr builds custom AI systems that read where our clients' work already happens, turn it into verified structured truth through layered extraction, and drive the programme views, registers, reporting, and calculated results their business runs on. This is the documentation behind that: how we protect the data, which models are permitted to see it, and where our program has gaps.

This is our general documentation. Anything specific to an engagement — its architecture, connector scopes, model register, or evaluation results — is shared with that client directly under NDA and never published here, which is equally true of every other client.

We do not hold a SOC 2 report, and we lead with that rather than burying it. The reason is scope: a SOC 2 opinion covers a defined system that has been operating, and we build bespoke software per client, so at the point you are reviewing us that system is being designed rather than running. We build to the Trust Services Criteria from the first commit, submit the delivered system to examination once it is live, and decline to offer substitutes that resemble assurance without being it. See exactly where we stand.

What we commit to

Six commitments govern every system we build. The confidential documents are the evidence for them, including the places where a commitment depends on which deployment model you choose.

Controlled AI processing

Client data is processed by models inside an agreed boundary: an enterprise endpoint under no-training, zero-retention terms, a model inside your own cloud tenancy, or open-weight models on compute you control. No client data trains any model.

Tenant isolation by separation

Each client has its own database, its own object storage, and its own credentials. There is no shared application datastore, so there is no query that could return another client’s data.

Least privilege integrations

Connections use an app registration you create, consent to, and can revoke without contacting us. We ask for the narrowest scope that works — site-by-site rather than whole-estate.

Encryption everywhere

TLS 1.2 or better in transit, AES-256 at rest. Credentials are held as Cloudflare Workers secrets, injected at runtime, never in code or logs, and rotated on personnel change and on any suspected exposure.

Provenance and audit trail

Every assertion links to the meeting, message, or document it came from, with a timestamp and the person who confirmed it. Every change and override stays attributable.

Human control

Consequential updates are proposed and confirmed by a named person, not applied autonomously. Our systems observe and advise; they never control physical or safety-critical operations.

At a glance

Company
Vectyr LLC, Lawrenceburg, KY, USA
Personnel with access
Three founders. No subcontractors, no offshore team
Hosting
Vectyr-operated on Cloudflare, with dedicated AWS or DigitalOcean compute where an engagement needs it
AI processing
Enterprise API under no-training, zero-retention terms — or self-hosted models where no third party sees your content
SOC 2
Not held — an opinion needs a built, operating system. We build to the criteria and submit the delivered system once live
ISO/IEC 27001
Not held — controls mapped to Annex A
HECVAT & CAIQ
Completed responses available
Data processing agreement
Available, and we will work from your template
Breach notification
Within 24 hours of becoming aware

Public documentation

Readable by anyone, no NDA required. These are summaries; the detail is in the confidential library.

Start here

What Vectyr builds, how we protect it, and how to run a review with us.

  • Security overview

    How Vectyr protects client data across the systems we build and operate, and what a reviewer should expect from us.

    v1.4 Updated August 11, 2026

  • Hosting, isolation, and AI processing

    Where Vectyr systems run, how each client's data is kept separate, and the two options for how AI models process it.

    v2.0 Updated August 11, 2026

  • AI governance

    Which models process client data, what they are permitted to see, how outputs stay explainable, and why our systems are not black boxes.

    v1.1 Updated August 11, 2026

  • Architecture and data flow

    The components of a Vectyr system, how data moves from source to verified record, and where the trust boundaries sit.

    v1.1 Updated August 11, 2026

  • How to run a security review with us

    A practical route through a Vectyr assessment, what we will hand over, and what we need from you.

    v2.1 Updated August 11, 2026

Data protection & privacy

Classification, retention, subprocessors, and privacy commitments.

  • Data protection and privacy

    What personal data our systems touch, the legal basis and roles involved, retention, and the rights we support.

    v1.2 Updated August 11, 2026

  • Subprocessors

    The third parties that may process client data on our behalf, what each does, and how we handle changes.

    v2.0 Updated August 11, 2026

Resilience & operations

Incident response, recovery objectives, backups, and availability.

Assurance & questionnaires

Control mappings and completed questionnaire responses for procurement.

  • Compliance and certifications

    Why a SOC 2 report cannot precede the system it would cover, what we build to instead, and the honest status of everything else.

    v2.0 Updated August 11, 2026

Confidential library

38 documents covering our full policy set, architecture detail with exact integration permission scopes, the AI model register, resilience plans with recovery objectives, completed HECVAT and CAIQ responses, our control framework crosswalk, and sector annexes for research institutions and critical infrastructure. Everything downloads as PDF.

Access takes about a minute: tell us who you are, accept a short NDA, and click the link we email to your work address.

Request access Read the NDA first

Security program

The policies and standards that govern how we build and operate.

  • Information security policy

    The governing policy for Vectyr's security program — scope, principles, roles, and the standards it delegates to.

    v1.1 Updated August 11, 2026 NDA required

  • Access control standard

    How identities, authentication, authorization, and privileged access are managed for Vectyr staff, end users, and service credentials.

    v1.0 Updated August 11, 2026 NDA required

  • Encryption and key management

    Cryptographic controls in transit and at rest, secret handling, rotation, and who holds keys in each deployment model.

    v2.2 Updated August 11, 2026 NDA required

  • Secure development lifecycle

    How code is written, reviewed, tested, and released, and the security requirements that apply at each stage.

    v1.1 Updated August 11, 2026 NDA required

  • Change management

    How changes to production systems are authorized, deployed, verified, and reversed.

    v1.2 Updated August 11, 2026 NDA required

  • Vulnerability and patch management

    How vulnerabilities are identified, triaged, and remediated, with target timelines by severity.

    v1.2 Updated August 11, 2026 NDA required

  • Logging, monitoring, and audit

    What we log, what we deliberately do not log, how long records are kept, and how clients get audit evidence.

    v1.3 Updated August 11, 2026 NDA required

  • Endpoint, asset, and workplace security

    How the devices and physical working arrangements of a fully remote team are secured.

    v1.2 Updated August 11, 2026 NDA required

  • Personnel security

    Screening, confidentiality obligations, security training, and the onboarding and offboarding process for anyone with access.

    v1.1 Updated August 11, 2026 NDA required

  • Acceptable use standard

    The rules governing how Vectyr personnel may use client data, AI tools, and company systems.

    v1.2 Updated August 11, 2026 NDA required

Architecture & deployment

Where systems run, how data moves, and which deployment model applies.

  • Architecture and data flow detail

    Component-level architecture, per-model egress paths, data stores, and the full set of network flows.

    v1.1 Updated August 11, 2026 NDA required

  • Tenancy and isolation

    How client data is kept separate, how separation is enforced and verified, and what happens at the edges.

    v1.3 Updated August 11, 2026 NDA required

  • Microsoft 365 and Teams integration security

    Exact Graph permission scopes, consent model, authentication method, and controls for Teams, SharePoint, and OneDrive connections.

    v1.1 Updated August 11, 2026 NDA required

  • Identity, single sign-on, and federation readiness

    Supported federation protocols, our SAML 2.0 and Shibboleth readiness profile, provisioning, and multi-factor inheritance.

    v1.0 Updated August 11, 2026 NDA required

  • Connector inventory

    Every integration type we build, the data it reads, the permissions it needs, and the questions to settle before connecting it.

    v1.0 Updated August 11, 2026 NDA required

AI governance

Which models we use, what they may process, and how humans stay in control.

  • AI model register

    The models and endpoints approved to process client data, their retention and training terms, and the rules for changing them.

    v2.0 Updated August 11, 2026 NDA required

  • Provenance and human oversight

    The data model behind every traceable assertion, how confirmation works, and what a reviewer can independently verify.

    v1.1 Updated August 11, 2026 NDA required

  • AI risk assessment

    The failure modes of the AI systems we build, their consequences, and the controls that reduce them.

    v1.1 Updated August 11, 2026 NDA required

  • AI evaluation and accuracy management

    How extraction quality is measured, what we report, and how prompt and model changes are gated.

    v1.2 Updated August 11, 2026 NDA required

Data protection & privacy

Classification, retention, subprocessors, and privacy commitments.

  • Data classification and handling

    Our classification tiers, how they map to client schemes, and the handling rules and deployment requirements for each.

    v1.2 Updated August 11, 2026 NDA required

  • Data retention and disposal

    Default retention by data category, deletion on request, and what happens to data when an engagement ends.

    v1.1 Updated August 11, 2026 NDA required

  • International data transfers and residency

    Where data is processed, transfer mechanisms, and how residency requirements in Europe and Asia are satisfied.

    v2.1 Updated August 11, 2026 NDA required

  • Data processing agreement and contractual commitments

    The security and privacy terms Vectyr will commit to contractually, including notification timelines and audit rights.

    v2.1 Updated August 11, 2026 NDA required

  • Vendor and subprocessor management

    How we assess, approve, monitor, and remove third parties that touch client data.

    v1.2 Updated August 11, 2026 NDA required

Resilience & operations

Incident response, recovery objectives, backups, and availability.

  • Risk management

    How Vectyr identifies, assesses, treats, and reviews information security risk.

    v2.0 Updated August 11, 2026 NDA required

  • Incident response plan

    How Vectyr detects, classifies, contains, and communicates security incidents, with committed notification timelines.

    v1.3 Updated August 11, 2026 NDA required

  • Business continuity and disaster recovery

    Recovery objectives, scenario-by-scenario recovery plans, and how continuity is assured for a small supplier.

    v1.3 Updated August 11, 2026 NDA required

  • Backup and restore

    What is backed up, how often, where it is held, how long it is kept, and how restores are tested.

    v1.2 Updated August 11, 2026 NDA required

  • Availability and service levels

    What we commit to on uptime, support response, and maintenance, and what we deliberately do not commit to.

    v1.3 Updated August 11, 2026 NDA required

  • Team, continuity, and portability

    Who builds and operates your system, and the measures that keep it yours regardless of what happens to us.

    v2.0 Updated August 12, 2026 NDA required

Assurance & questionnaires

Control mappings and completed questionnaire responses for procurement.

  • Control framework crosswalk

    Vectyr's controls mapped to SOC 2, ISO/IEC 27001 Annex A, and NIST CSF 2.0, with an implementation status for each.

    v2.0 Updated August 11, 2026 NDA required

  • HECVAT response

    Vectyr's narrative response to the Higher Education Community Vendor Assessment Toolkit, by domain.

    v2.2 Updated August 11, 2026 NDA required

  • CSA CAIQ response

    Vectyr's response to the Cloud Security Alliance Consensus Assessments Initiative Questionnaire, by control domain.

    v2.3 Updated August 11, 2026 NDA required

  • Penetration testing and security assessment program

    How we test, the roadmap for independent testing, and how to commission your own at no charge.

    v1.2 Updated August 11, 2026 NDA required

  • Accessibility conformance

    Our conformance against WCAG 2.1 Level AA, how we test, and how we handle accessibility review.

    v1.2 Updated August 11, 2026 NDA required

  • Corporate information

    Corporate details and the diligence artifacts procurement teams normally request.

    v3.0 Updated August 11, 2026 NDA required

Sector annexes

Additional controls for research institutions and critical infrastructure.

  • Research institution annex

    Additional controls for universities, academic medical centres, and research departments, covering human subjects, health data, student records, and sponsored research.

    v2.2 Updated August 11, 2026 NDA required

  • Critical infrastructure annex

    Additional controls for ports, terminals, and industrial operators, covering the operational technology boundary, safety, and sensitive operational data.

    v1.1 Updated August 11, 2026 NDA required

Contact

Security issues and vulnerability reports: trust@vectyr.co. We acknowledge within one business day. See our disclosure policy for scope and safe-harbour terms.

Questionnaires, agreements, and procurement: trust@vectyr.co. Send us your questionnaire in your own format and we will complete it.