How we protect your project data
Where it sits, who can reach it, and what the model receives.
Updated2026-08-16
ResidencyAWS Canada (Central)
Writes to your systemsNone
01
Our posture
- Residency
- Your records, documents, generated analysis and backups are stored in AWS Canada (Central), encrypted at rest, TLS 1.2 or later in transit.
- Read-only
- Vecreal writes nothing back. It holds no send or write scope on any connected system and cannot send an email or change a record in your project management system. Your existing tools stay the system of record.
- Isolation
- Tenant isolation is enforced in the database with PostgreSQL row-level security and a non-bypass application role. Project scope is enforced on every read and write.
- Model use
- Your data is not used to train any model, ours or a provider’s. Requests
carry only the project context needed for the task, with provider-side conversation
storage and prompt caching disabled. Model providers are approved at the firm level.
Model processing may occur outside Canada. Under our provider’s standard API controls, limited content may be retained in abuse-monitoring logs for up to 30 days.
- Project content only
- Email is screened before it enters the retained project corpus. Personal or non-project content is excluded rather than stored.
- Access
- Microsoft Entra ID is the default sign-in path, so your MFA and Conditional Access policies apply and you can revoke at any time. Vecreal staff access is limited to named personnel on least privilege and is audited.
- Deletion
- Your data is permanently deleted from live systems on request or at the end of an engagement, with an export first if you want one. Encrypted backups expire on a fixed 30-day window.
02
Compliance status
We identify a certification as achieved only after the applicable independent assessment is complete, and this page is where that would first appear.
SOC 2
Certification in progress
Program build toward Type I, then Type II.
ISO 27001
Certification in progress
Built to ISO 27001 standards, sequenced after SOC 2.
PIPEDA and provincial privacy law
Compliant
Aligned to PIPEDA and the provincial statute that applies where a customer
operates, including Alberta PIPA and BC PIPA. There is no certification path for these.
AWS maintains its own certifications for the underlying cloud services we build on.
Under agreement
Full architecture and data-flow documentation, a data processing agreement, service levels, sub-processor detail, penetration test results and security questionnaire responses are provided under a commercial agreement rather than published here.
03
Reaching us
- Security concerns
- Found a vulnerability, or have a security question about Vecreal? Get in touch and it reaches the founders directly.
- Under agreement
- Response targets, incident-notification commitments, the data processing agreement, service levels and penetration test results form part of a commercial agreement rather than being published here.