Security

What is in place to protect customer data, the limits of what is published here, and who to contact for a review. This page describes controls you can inspect; it does not claim a certification.

Controls in the product

Workspace access controls

Workspace membership checks gate access to brands, audits and settings. Sensitive actions require an authenticated owner or admin session, not a front-end check.

API key controls

API keys carry scoped permissions, an expiry and per-key rate limits. Key-management actions have stricter server-side throttling.

Webhook safeguards

Deliveries are signed, recorded and validated. Endpoint URLs are screened to block localhost, private-network and metadata targets before a delivery is allowed.

Security visibility

Security events, audit activity, delivery history and retention settings are visible inside the workspace.

Practices

Data protection

  • Workspace-scoped access checks on customer data
  • Configurable retention settings in the workspace
  • Account and workspace deletion flows in the product
  • Public privacy and DPA documentation

Application security

  • Server-side authorization checks on protected routes
  • Schema validation on key API mutations
  • Rate limiting for API requests and critical actions
  • Webhook URL validation to reduce SSRF risk

API security

  • API keys with scoped permissions
  • Bearer-token authentication for API routes
  • Signed webhook deliveries
  • Webhook delivery history and testing

Operational security

  • A security contact for review requests
  • In-product security event visibility
  • Admin audit logs for key actions
  • Privacy and legal escalation paths

Documents you can read now

A security review usually starts with the documents and contacts a customer can check before a deeper conversation. These are public:

Documents alone are not a certification. If your review needs a signed DPA or answers to a questionnaire, ask below.

Questions

How does VectorGap protect customer data?
With workspace-scoped access checks, admin restrictions on sensitive actions, scoped API keys, webhook signing and server-side rate limiting. Security-event and retention controls are exposed inside the workspace so teams can review activity and data-management settings.
Is VectorGap GDPR compliant?
VectorGap publishes its privacy policy and a DPA, and the product includes retention and deletion controls. If you need a signed DPA, procurement documentation or the current legal posture for a review, contact us directly.
What security certifications does VectorGap have?
None are claimed on this page. It describes controls and documents you can inspect today. For vendor questionnaires, audits or certification status, ask during your security review.
How do I report a security vulnerability?
Email security@vectorgap.ai with a clear description and steps to reproduce. Reports are reviewed by hand. Please avoid accessing customer data or disrupting the service while testing.

Contact

Security reviews and vulnerability reports: security@vectorgap.ai. Anything else: the contact page.