Back to vectrapex.ai

Security & your data

Your data stays yours

Automating a workflow means giving someone access to the tools your business runs on. That is a real thing to hand over, and it deserves a straight answer rather than a badge. Below is exactly how we work — eight commitments that hold on every build we ship, and a plain statement of what we don't claim.

Send this page to whoever asks. Last updated 22 August 2026.

  1. 01

    We never train models on your data

    Not yours, not your customers'. Your data moves through a workflow to do a job. That's where it ends.

    Nothing that passes through an automation we build is retained to improve a model, ours or anyone else's. We don't keep a copy to "learn from later", and we don't reuse one client's data to build another client's agent.

  2. 02

    Least-privilege access

    We connect through official integrations and ask for only the permissions a workflow actually needs. Never a blanket key to everything.

    In practice that means a documented list of scopes before we start, granted through the provider's own consent screen — not a shared password. An agent that reads enquiries and writes a calendar entry gets exactly those two permissions and nothing more.

  3. 03

    A human in the loop where it counts

    Anything that spends money, goes to a customer, or can't be undone waits for a person to approve it.

    We agree the line in writing before we build: what the agent may do on its own, what it must hand to a person, and what it must never attempt. Those limits are enforced in the build, not left to the model's judgement.

  4. 04

    Your data stays where it already lives

    We build on top of the tools you already use instead of copying your business into ours. No shadow database on our side.

    Your records stay in your CRM, your sheets, your inbox. We don't stand up a parallel copy of your business that you'd then have to worry about, audit, or get back if we parted ways.

  5. 05

    Encrypted in transit

    Every connection we build runs over TLS. Table stakes — but worth saying plainly.

  6. 06

    We'll sign your NDA

    Send yours over before the audit call. We don't need access to anything sensitive to tell you what's worth automating.

    The free audit is a conversation about how work moves through your business. It needs no logins, no exports and no customer records.

  7. 07

    Revoke or delete, any time

    Pull our access yourself from your own tool's settings, and ask us to delete anything we hold. No exit negotiation.

    Because access is granted through each provider's own consent screen, revoking it never depends on us doing anything. You don't need our cooperation to cut us off.

  8. 08

    Built on reputable frontier models

    We use the business APIs of established providers, whose terms bar training on the data sent through them.

    We'll tell you which providers a given build uses, so your own team can check their terms rather than take our word for it.

What we don't claim

We're not SOC 2 certified or HIPAA-audited, and we won't pretend otherwise. We're a small team, and the honest position is that we hold ourselves to the commitments above rather than to an audit we haven't sat.

If your security team needs specifics before we start — which scopes, which providers, where a particular field ends up — ask us directly. You'll get a straight answer, including "we don't do that" where it applies.

Questions your IT team wants answered?

Send them this page, then send us the questions it doesn't cover.