Your data. Your keys. Your tenant.
Vertex is built so the most important things stay yours. Provider keys live encrypted in your own workspace, customer data is isolated per tenant, and every AI action is scoped, gated and audited. Here's exactly how that works — described honestly, with nothing we don't actually do.
Your keys & your data
Provider keys are stored encrypted inside your workspace — never shared between tenants — and customer data is isolated per tenant. Export it anytime.
- Stripe, Postmark, Telnyx & AI keys, encrypted
- Bring your own accounts; rotate or revoke any time
- Full export in open formats, on demand
Encrypted in transit & at rest
All traffic is served over TLS. Data is encrypted at rest on disk, and sensitive secrets get an extra application-layer encryption key on top.
- HTTPS/TLS everywhere
- At-rest encryption on disk
- Dedicated key for secret material
Tenant isolation & least privilege
Every query is scoped to your workspace on the server, and access follows least-privilege roles — people and AI only ever see what their role allows.
- Server-side tenant scoping on every read
- Role-based access control
- No co-mingling of customer data
GDPR built in
Privacy tooling ships with the product: consent capture, DSAR export, deletion and erasure, and per-workspace retention settings you control.
- Consent capture & tracking
- Data-subject access export (DSAR)
- Deletion / erasure & retention windows
Bare-metal infrastructure
Production runs on dedicated bare-metal servers — no Docker in production. A simple, auditable stack we control end to end, with fast, predictable performance.
- Hetzner dedicated Ubuntu hosts
- systemd services + Caddy TLS
- No container orchestration in prod
Audited, gated AI actions
The assistant runs with your permissions, logs every tool call, and routes money or bulk operations through an approval gate — nothing irreversible happens without your go.
- Permission-scoped tool calls
- Full audit trail of every action
- Approval gates on money & bulk changes
It's your business. So it's your data.
Most CRMs make your data, and your provider keys, theirs. Vertex flips that: you bring the accounts you already pay for, we hold them encrypted on your behalf, and you can take everything with you the day you decide to leave.
- Provider keys stay encrypted in your workspace
- Customer data isolated to your tenant alone
- Export contacts, deals, billing and events anytime
- Rotate or revoke any integration with one click
- Cancel and keep your records — no hostage data
Sub-processors.
The services Vertex may rely on to deliver the product. Where you bring your own keys, your data flows to your own accounts with these providers under their terms.
Stripe
Payments, subscriptions and billing — used with your own Stripe account and keys.
Postmark
Transactional email delivery, connected with your own sending domain and keys.
Telnyx
SMS, voice and telephony, run through your Telnyx account and credentials.
Calendar and Workspace sync, and Gemini AI — authorised with your own Google connection.
Anthropic
Claude AI for the assistant and autopilot, used with your configured AI key.
Bunny
Edge CDN and media delivery for fast, global static and asset serving.
Note: Vertex is not yet formally certified (e.g. SOC 2). This page describes the practices we follow today — we're glad to share more detail with prospective Enterprise customers.
Questions, answered.
Where are my provider keys stored?
Provider keys — Stripe, Postmark, Telnyx, AI and others — are stored encrypted inside your own workspace, not shared across tenants. You connect the accounts you already pay for, we use them on your behalf, and you can rotate or revoke them at any time.
Is my data isolated from other customers?
Yes. Every record is scoped to your workspace (tenant). Queries are filtered by tenant on the server, access follows least-privilege roles, and your customer data is never co-mingled with another tenant's.
Is my data encrypted?
All traffic is served over TLS (HTTPS) in transit, and data is encrypted at rest on disk. Sensitive secrets such as provider keys are additionally encrypted at the application layer with a dedicated key.
How do you handle GDPR requests?
GDPR tooling is built in: consent capture, data-subject access (DSAR) export, deletion/erasure, and per-workspace retention settings. You can fulfil access and deletion requests directly from the app.
Are you SOC 2 certified?
We are not yet formally certified. This page describes the security practices we follow today — encryption, tenant isolation, least-privilege access, audited AI actions and GDPR tooling. We're happy to share more detail with prospective Enterprise customers.
Can the AI assistant do something irreversible?
No. AI actions are scoped to your permissions, audited on every call, and money or bulk operations route through an approval gate. The assistant proposes a result card and waits for your go before anything commits.
Built so your data stays yours.
Start a 14-day trial — bring your own keys, keep full ownership, and take everything with you whenever you like.