ecreal

How we protect your project data

Where it sits, who can reach it, and what the model receives.

Updated2026-08-16
ResidencyAWS Canada (Central)
Writes to your systemsNone
01

Our posture

Residency
Your records, documents, generated analysis and backups are stored in AWS Canada (Central), encrypted at rest, TLS 1.2 or later in transit.
Read-only
Vecreal writes nothing back. It holds no send or write scope on any connected system and cannot send an email or change a record in your project management system. Your existing tools stay the system of record.
Isolation
Tenant isolation is enforced in the database with PostgreSQL row-level security and a non-bypass application role. Project scope is enforced on every read and write.
Model use
Your data is not used to train any model, ours or a provider’s. Requests carry only the project context needed for the task, with provider-side conversation storage and prompt caching disabled. Model providers are approved at the firm level.

Model processing may occur outside Canada. Under our provider’s standard API controls, limited content may be retained in abuse-monitoring logs for up to 30 days.

Project content only
Email is screened before it enters the retained project corpus. Personal or non-project content is excluded rather than stored.
Access
Microsoft Entra ID is the default sign-in path, so your MFA and Conditional Access policies apply and you can revoke at any time. Vecreal staff access is limited to named personnel on least privilege and is audited.
Deletion
Your data is permanently deleted from live systems on request or at the end of an engagement, with an export first if you want one. Encrypted backups expire on a fixed 30-day window.
02

Compliance status

We identify a certification as achieved only after the applicable independent assessment is complete, and this page is where that would first appear.

SOC 2 Certification in progress Program build toward Type I, then Type II.
ISO 27001 Certification in progress Built to ISO 27001 standards, sequenced after SOC 2.
PIPEDA and provincial privacy law Compliant Aligned to PIPEDA and the provincial statute that applies where a customer operates, including Alberta PIPA and BC PIPA. There is no certification path for these.

AWS maintains its own certifications for the underlying cloud services we build on.

Under agreement

Full architecture and data-flow documentation, a data processing agreement, service levels, sub-processor detail, penetration test results and security questionnaire responses are provided under a commercial agreement rather than published here.

03

Reaching us

Security concerns
Found a vulnerability, or have a security question about Vecreal? Get in touch and it reaches the founders directly.
Under agreement
Response targets, incident-notification commitments, the data processing agreement, service levels and penetration test results form part of a commercial agreement rather than being published here.