Security
Built for the most confidential room in the building.
Exactly what's in place today, in line with our Privacy Policy, not what's on a roadmap.
01Hosting & infrastructure
Vaultrix runs on Microsoft Azure: a containerised application (Azure Container Apps), a dedicated Azure Database for PostgreSQL, and Azure Blob Storage for uploaded files in production. There's no shared infrastructure with unrelated products.
02Document processing
Document indexing and embedding are performed on Vaultrix's own infrastructure, not sent to a third-party embeddings API. Text only leaves our servers when a question is answered, and even then only the specific evidence chunks needed for that answer are sent to an AI provider, never a whole document, and never the whole data room.
03Encryption
Data is encrypted at rest and in transit using standard cloud-provider encryption. We don't yet issue dedicated per-deal encryption keys; that's realistic for a large enterprise engagement, reach out if it's a requirement for yours.
04Access control & deal isolation
Retrieval, uploads, and document downloads are all scoped to a single deal and enforced server-side. A user needs an explicit membership on a deal, not just membership in your organisation, before they can query it, upload to it, or view its documents.
Documents are never served from a public or predictable URL. Every file read re-authorises through the same per-user, per-deal check, even though the caller already had to know the file's ID, and downloads are logged to the audit trail.
05Activity logging & deletion
Questions asked, document views, uploads, and review decisions are logged with who and when, for audit and dispute-resolution purposes. There's no export tool for that log yet.
Deleting a deal removes its files from storage and its rows from the database, permanently. It's a real deletion, not a soft delete, and it isn't reversible, so we don't issue a separate deletion certificate beyond the deletion itself.
06AI provider privacy
Answering a question calls Anthropic's API, and optionally OpenAI's for a limited rewrite pass over an already-cited draft. Under their standard API terms, neither provider trains on your inputs or outputs by default. We haven't signed a separate zero-retention addendum with either provider yet. If that's a hard requirement for your deal, tell us before you upload anything sensitive.
07Certifications
Vaultrix has not yet pursued SOC 2, ISO 27001, or a formal third-party penetration test. We'd rather say that plainly than claim something we can't back up.
What we can point to concretely is everything above: server-side access control enforced on every deal, in-house document processing, and a human sign-off required before any AI finding counts as final. If a formal certification is a hard requirement today, contact us before you sign up and we'll talk through what we can commit to.
08Contact
For security questions, disclosures, or reports: admin@vaultrix.ai.