LEGAL
Last updated [EFFECTIVE DATE]
Vortel acts on behalf of your team, so it is built to do only what you allow and to keep a record of everything it does. This page describes the controls in the platform today.
Draft for review. Fields in brackets are pending confirmation.
Each workspace is kept separate. Isolation is enforced on every query, every cache key and every call to an outside provider, so data from one workspace stays inside that workspace.
Three roles, Admin, Operator and Viewer, cover eight permissions. Permissions are enforced on the server for every request, not only hidden in the interface.
Each workspace chooses how much Vortel can do on its own: full auto, review LinkedIn, or review everything. Actions with side effects, such as sending a message, pass through approval gates.
Access tokens last 15 minutes and refresh tokens last 7 days. Sessions can be revoked through three independent mechanisms.
Internal services authenticate each other with signed tokens that expire within 5 minutes. Incoming webhooks from payment, email, telephony and authentication providers are verified by cryptographic signature.
Requests are rate limited per IP address and per workspace.
Every action Vortel takes is written to an immutable log, and agent sessions are kept as transcripts, so you can see what happened, when and why. Credit usage is tracked in an append-only ledger.
Email, calendar and LinkedIn accounts are connected through each provider's own authorization flow. Vortel does not store the passwords for those accounts.
Vortel keeps what the work needs. For example, it stores birth year rather than full date of birth, and it does not store credentials.
If you believe you have found a security issue, write to [SECURITY EMAIL]. [DISCLOSURE POLICY]
For security questionnaires or more detail, write to [SECURITY EMAIL].