What Vectyr does, in security terms
Vectyr builds and operates custom AI software for a small number of enterprise clients. The systems share a shape, though not a simple one.
They connect to where the work already happens — Microsoft Teams meetings and chat, SharePoint and OneDrive, email, line-of-business and operational APIs, data warehouses, sensor and equipment telemetry, and whatever else a client’s work actually runs through.
They turn that material into structured meaning through a layered pipeline, not a single model call. Deterministic parsing and rules handle what code can do reliably. Classifiers route, filter, and label. Multiple models, chosen per task and versioned independently, extract entities, relationships, commitments, and change. Later stages reconcile what earlier stages produced against what the system already knows, resolve conflicts, and attach a confidence signal and a pointer back to the exact source. Extraction quality is measured against a client-approved evaluation set rather than assumed.
A named human confirms anything consequential before it becomes authoritative, per field rather than wholesale, with the source sentence in front of them.
What comes out of that layer is where the value is, and it is open-ended by design: a confirmation inbox and approval flow for each owner; live timelines, milestones, and dependency graphs; risk, issue, action, and decision registers; delay and knock-on-effect detection; resourcing and workload views; vendor and delivery performance; KPI trees linking programme work to business outcomes; a connected knowledge base answerable in natural language with citations; generated reporting for any audience; triggered workflows; and an effectively unlimited set of calculated results specific to how that business measures itself. Two clients running the same pipeline end up with materially different systems, because the outputs are modelled on their operation rather than ours.
That shape determines our security posture. We are not a self-serve SaaS product with thousands of tenants. We run a small number of dedicated systems, each holding one client’s data, each connected to that client’s identity provider and file estate. The risks that matter most are therefore integration scope, tenant isolation, credential handling, and control over what AI models are permitted to see. Those are the areas where our controls are deepest, and they are the areas we expect a reviewer to press hardest.
The commitments behind our architecture
Six commitments govern every system we build. They appear in our proposals, and the confidential documents in this trust center are the evidence for them.
Controlled AI processing. Client data is processed by models running inside an agreed boundary: either an enterprise inference endpoint under contractual zero-retention and no-training terms, or open-weight models running on infrastructure we operate for that client alone, where no third party receives the content at all. We do not send client data to consumer AI products, and no client data is used to train any shared or third-party model. See AI governance for what each option actually means.
Tenant isolation. Each client’s data lives in its own datastore, reached by its own credentials, deployed as its own instance. There is no shared application database holding several clients’ records, so there is no query that could return another client’s data.
Least privilege. People, service integrations, and automated agents get the narrowest access that lets them do their job. Integration scopes are read-only wherever a read is sufficient, and end-user visibility can be inherited from the client’s own group memberships rather than maintained as a second, drifting list of permissions.
Encryption everywhere. Data is encrypted in transit with TLS 1.2 or better and encrypted at rest by the underlying platform. Credentials, API keys, and OAuth tokens are held in a managed secret store, never in source code or configuration files, and are rotated on personnel change and on any suspected exposure.
Provenance and audit trail. Every fact a system asserts is linked to the source it came from — the meeting, message, document, or API response — with a timestamp. Every human confirmation, edit, and override is attributed and retained. This is a product feature as much as a control: a reviewer, an auditor, or a sceptical colleague can ask “how do you know that?” and get an answer.
Human control and retention limits. Consequential updates are proposed by the system and confirmed by a person, not applied autonomously. Data is kept only as long as the engagement and the client’s retention rules require, and is returned or destroyed on request.
How we are set up as a company
Vectyr LLC is a small, founder-operated firm. Three founders hold all administrative access; there are no offshore development teams and no subcontracted engineers with access to client systems. Every person with access to a client environment is a named individual who has signed confidentiality obligations and completed security onboarding.
This structure is a genuine advantage for a security reviewer. The access list is short, complete, and verifiable in a single page. Every change is reviewed by someone who understands the whole system rather than one component of it. There is no ambiguity about who is accountable, and the person who built your system is the person who answers your questions.
Continuity is engineered rather than assumed: all three principals can operate any client system end to end, your data is exportable in conventional formats at any time, and escrow, configuration mirroring, and a contractual transition commitment are available in every engagement. See Team, continuity, and portability.
Certification and assurance
On SOC 2, the position is a matter of scope rather than of standards. A SOC 2 report is an auditor’s opinion on a defined system, describing controls that were operating over a period. We build bespoke software per client, so at the point you are reviewing us, the system that will hold your data is being designed rather than running. There is no operating period to examine.
So we do three things instead. We build to the Trust Services Criteria from the first commit, so the delivered system is auditable by design rather than retrofitted. We will pursue an examination scoped to your system once it is live and operating, if your requirements call for one, and we will accept that as a contractual milestone. And we decline to offer substitutes that would look like assurance without being it — including a report on Vectyr’s own internal systems, which are fully isolated from client deployments and hold no client data, and our platform provider’s certificates, which cover their layer and not our practices.
We may name clients as references where they have agreed to be named, but we never disclose any client’s security posture, architecture, controls, or assessment results, and we would not offer another client’s audit status as evidence about us. The same line protects you.
Compliance and certifications sets out the full position, the path to an audited system, and what to rely on in the meantime. The control framework crosswalk maps every control we operate to SOC 2, ISO/IEC 27001 Annex A, and NIST CSF 2.0, so a reviewer can locate the evidence for a given criterion directly.
Reporting a security problem
If you believe you have found a vulnerability in anything Vectyr operates, please tell us at trust@vectyr.co, which reaches all three founders. We will acknowledge within one business day. Our vulnerability disclosure policy sets out scope, safe-harbour terms, and what to expect from us.
What is here, and what is not
This trust center describes how Vectyr works in general. It is deliberately not a status board for individual engagements: nothing specific to your system — its architecture document, connector inventory, model register, data-flow diagrams, evaluation results, or the status of any examination scoped to it — is published here or will be. That material is prepared for you and shared directly under NDA, discussed live with your team, and kept between us. The same holds in reverse, which is the point: no other client’s engagement detail appears here either.
Getting the detail
The public pages here are summaries. The policies, standards, architecture detail, questionnaire responses, resilience plans, and sector annexes are confidential and available after a short NDA acceptance, which takes about a minute. Request access, or read how to run a security review with us if you are planning a formal assessment.