Security & Trust

Security built into the foundation — not bolted on.

Vertiqa runs the calls, messages, documents, and customer records your business depends on. We protect them with tenant isolation by design, encryption everywhere, and AI that drafts and recommends — but never sends on its own.

No autonomous outboundAES-256 encryptionSOC 2 on our roadmapsecurity@vertiqa.io
The request pathlive · append-only
Your team & APISessions & keys
ConnectorsSigned & verified
AI agentsDraft & recommend
External AI & MCPAgents · Claude · tools
Governed path
Every request,
verified.
Authenticated, scoped, permission-checked, and human-approved before it can touch data.
AuthenticateScopePermissionApproveKernelRLS
Your dataEncrypted · isolated
Audit timelineEvery action logged

Isolated per organization

A strict tenant boundary on every request

Encrypted in transit & at rest

TLS everywhere, AES-256-GCM for secrets

A human approves outbound

Agents draft; people review and send

Full audit trail

Every action on one timeline you can see

Our principles

Three things we don’t compromise on

Security at Vertiqa is architectural — it’s how the system is built, not a layer we added afterward.

Isolated by construction

Your data lives behind a strict tenant boundary. Every request is scoped to your organization, every table enforces row-level isolation, and every endpoint requires an explicit permission before it returns a byte. It’s how the system is built — not a setting you can forget to turn on.

Protected by default

Data is encrypted in transit and at rest. Credentials and third-party secrets are encrypted with AES-256-GCM and stored apart from your business data. Insecure code patterns are caught and blocked before a change can ever ship.

AI you stay in control of

Our agents pursue goals inside guardrails, but they draft and recommend — a human approves and executes. Vertiqa’s AI agents never send outbound messages to your customers on their own, and every action is written to an audit trail you can see.

The controls

How we protect your data, control by control

Reassurance up top; the specifics your security reviewer will ask for, right here.

Tenant isolation & access

  • Every request is authenticated and scoped to your org; cross-org access is blocked at the API and the database.
  • Role-based permissions gate every operation — not just logins.
  • Automated cross-tenant tests run continuously and expand over time.

Encryption & secrets

  • TLS for data in transit; encryption at rest for the database.
  • Tokens and connector credentials encrypted with AES-256-GCM, keys held outside the codebase.
  • Security tokens use cryptographic randomness at 256-bit strength.

Authentication

  • Runs on a managed identity provider; passwords are hashed with industry-standard algorithms, never stored in plaintext.
  • OAuth uses the authorization-code flow with CSRF-protected state and auto-deactivates on repeated failure.

Secure by default in how we build

  • A written ruleset aligned to the OWASP Top 10 is mandatory — violations block merges.
  • Input validated, output encoded, errors never leak internals, dependencies continuously audited.

Full audit trail

  • A shared timeline records significant actions — human or agent — as they happen.
  • A separate, append-only compliance log captures governance-critical events.

AI & agent governance

  • Human-in-the-loop by default: agents recommend and draft; people approve and execute.
  • Agents operate through the same permission and tenant boundaries as your team.
  • Detected payment-card numbers are redacted from voice transcripts before storage.

Connector & webhook security

  • Integrations use OAuth 2.0 / PKCE; stored credentials are encrypted and least-privilege.
  • Inbound webhooks require verified, timing-safe signatures and reject replays.

Infrastructure

  • Runs on Azure with managed PostgreSQL, infrastructure-as-code, and automated CI/CD.
  • HSTS and hardened transport defaults across the platform.

The guarantee

AI agents never send outbound messages on their own.

Agents do real work — gathering context, drafting replies, recommending next steps. But before an agent-drafted message goes out to your customers, a person reviews and approves it. It’s not a policy we ask you to trust; it’s enforced in the request path.

Same permission & tenant walls as your teamEvery agent action written to the timeline

Agent works

Gathers context, drafts, recommends

Human approves

A person reviews and decides

Executed & logged

Through the kernel, onto the timeline

Compliance & privacy

Built for regulated, relationship-driven work

We’ll tell you exactly where we are — including what we haven’t earned yet.

Your data is yours

You decide what goes in. Reach out about exporting or deleting your organization’s data and we’ll walk you through it.

Designed for regulated work

Tenant isolation, encryption, least-privilege access, and auditability are the foundation — built for businesses that handle personal information.

On our roadmap

SOC 2 on the roadmap

SOC 2 and the attestations our regulated verticals expect are on our roadmap. We are not certified today — and we won’t claim what we haven’t earned.

Working through a vendor review?

Reach out and we’ll work through your data-handling, subprocessor, and security questions with you.

Responsible disclosure

Found something? We want to hear from you.

Email security@vertiqa.io. We investigate every report and keep you updated. Please give us reasonable time to remediate before any public disclosure.

Trusted by

  • AgentVerticalAI
  • AlHiba
  • AmeyaAI
  • Blinkr
  • EquiB
  • HRSanad
  • LandMyJobAI
  • Machi Finserv
  • Swaas
  • Tech North Atlanta
  • Tech Passionate
  • TruSkillAI
  • Venture Studios Hub