Security
What is in place to protect customer data, the limits of what is published here, and who to contact for a review. This page describes controls you can inspect; it does not claim a certification.
Controls in the product
Workspace access controls
Workspace membership checks gate access to brands, audits and settings. Sensitive actions require an authenticated owner or admin session, not a front-end check.
API key controls
API keys carry scoped permissions, an expiry and per-key rate limits. Key-management actions have stricter server-side throttling.
Webhook safeguards
Deliveries are signed, recorded and validated. Endpoint URLs are screened to block localhost, private-network and metadata targets before a delivery is allowed.
Security visibility
Security events, audit activity, delivery history and retention settings are visible inside the workspace.
Practices
Data protection
- Workspace-scoped access checks on customer data
- Configurable retention settings in the workspace
- Account and workspace deletion flows in the product
- Public privacy and DPA documentation
Application security
- Server-side authorization checks on protected routes
- Schema validation on key API mutations
- Rate limiting for API requests and critical actions
- Webhook URL validation to reduce SSRF risk
API security
- API keys with scoped permissions
- Bearer-token authentication for API routes
- Signed webhook deliveries
- Webhook delivery history and testing
Operational security
- A security contact for review requests
- In-product security event visibility
- Admin audit logs for key actions
- Privacy and legal escalation paths
Documents you can read now
A security review usually starts with the documents and contacts a customer can check before a deeper conversation. These are public:
Documents alone are not a certification. If your review needs a signed DPA or answers to a questionnaire, ask below.
Questions
- How does VectorGap protect customer data?
- With workspace-scoped access checks, admin restrictions on sensitive actions, scoped API keys, webhook signing and server-side rate limiting. Security-event and retention controls are exposed inside the workspace so teams can review activity and data-management settings.
- Is VectorGap GDPR compliant?
- VectorGap publishes its privacy policy and a DPA, and the product includes retention and deletion controls. If you need a signed DPA, procurement documentation or the current legal posture for a review, contact us directly.
- What security certifications does VectorGap have?
- None are claimed on this page. It describes controls and documents you can inspect today. For vendor questionnaires, audits or certification status, ask during your security review.
- How do I report a security vulnerability?
- Email security@vectorgap.ai with a clear description and steps to reproduce. Reports are reviewed by hand. Please avoid accessing customer data or disrupting the service while testing.
Contact
Security reviews and vulnerability reports: security@vectorgap.ai. Anything else: the contact page.
