How Vektor stores, protects, and processes your data: where it lives, who can access it, and what the AI does with it.
Hosted in Frankfurt (Render + Supabase), encrypted in transit and at rest.
Row-level security in the database. One customer can never read another’s data. Every API request is re-authenticated on the server.
Not by Anthropic, our AI provider. Not by Vektor. Your raw deal content is used for one purpose: generating your briefs.
Stripe is our merchant of record and handles all payment processing (PCI DSS Level 1).
A DPA, a published sub-processor list with 30 days’ change notice, breach notification within 48 hours, and deletion within 30 days when you leave.
Our infrastructure providers (Supabase, Render, Anthropic, Stripe) hold SOC 2 Type II or PCI DSS Level 1 certifications today. Security questionnaires answered on request.
Every system that stores your data sits in the EU. The one non-EEA transfer is covered by EU Standard Contractual Clauses.
The three questions security reviewers ask about the AI, answered.
No. Anthropic’s commercial terms prohibit training on API inputs and outputs. Inputs sent for generation are deleted by Anthropic within 30 days of the request, sooner under a zero-retention agreement.
No. Your raw deal content is used for one purpose: generating your briefs and coaching. Vektor does not build or train models on it.
Only in aggregated, de-identified form that cannot identify your company or any individual, for example patterns like where deals of a given type tend to stall. This is set out in our Privacy Policy and DPA, and it never includes your raw deal content.
Everything your security or legal team needs for a vendor review.
Questions, security questionnaires, or vendor-review requests: contact@vektorhq.ai. Vektor HQ, Denmark (CVR 46519779), supervised by Datatilsynet.