Security

    The controls that exist today, stated without certification claims.

    This page is limited to controls and infrastructure that are present in the product and repository now.

    Access and isolation

    Workspace boundaries

    Row-level isolation

    Multi-tenant workspace isolation is enforced with Postgres row-level security in Supabase.

    Authenticator-app MFA

    Users can enroll and manage a TOTP authenticator from the Security section in Settings.

    Infrastructure

    Service boundaries

    Hosting

    The application runs on DigitalOcean, the database is on Supabase, and DNS and edge delivery use Cloudflare.

    Payments

    Payments use Stripe Checkout, so card data does not touch Vertica servers.

    Email

    Transactional email is delivered through Resend.

    Application controls

    Credentials and events

    Integration credentials

    Customer-supplied integration API keys are encrypted at rest.

    Workspace audit trail

    The application records workspace events in an audit trail.

    Browser protections

    Vertica enforces a Content-Security-Policy and additional security headers.

    Workspace deletion

    Workspace deletion is available on request through support.

    Vendors

    Purpose-limited data sharing

    Data is sent to AI vendors solely to produce the output the customer requests. Review the vendor disclosure and the live status page.

    Request access

    Bring your next vertical plan into one shared workspace.

    Registrations are invite-only. Join the waitlist to request access.

    Access is invite-only. We invite from the waitlist, oldest first.