LEGAL

Security

Last updated [EFFECTIVE DATE]

Vortel acts on behalf of your team, so it is built to do only what you allow and to keep a record of everything it does. This page describes the controls in the platform today.

Draft for review. Fields in brackets are pending confirmation.

Workspace isolation

Each workspace is kept separate. Isolation is enforced on every query, every cache key and every call to an outside provider, so data from one workspace stays inside that workspace.

Roles and permissions

Three roles, Admin, Operator and Viewer, cover eight permissions. Permissions are enforced on the server for every request, not only hidden in the interface.

Autonomy you control

Each workspace chooses how much Vortel can do on its own: full auto, review LinkedIn, or review everything. Actions with side effects, such as sending a message, pass through approval gates.

Sign-in and sessions

Access tokens last 15 minutes and refresh tokens last 7 days. Sessions can be revoked through three independent mechanisms.

Service authentication

Internal services authenticate each other with signed tokens that expire within 5 minutes. Incoming webhooks from payment, email, telephony and authentication providers are verified by cryptographic signature.

Rate limiting

Requests are rate limited per IP address and per workspace.

A record of every action

Every action Vortel takes is written to an immutable log, and agent sessions are kept as transcripts, so you can see what happened, when and why. Credit usage is tracked in an append-only ledger.

Connected accounts

Email, calendar and LinkedIn accounts are connected through each provider's own authorization flow. Vortel does not store the passwords for those accounts.

Data minimization

Vortel keeps what the work needs. For example, it stores birth year rather than full date of birth, and it does not store credentials.

Protecting recipients and your domain

Reporting a vulnerability

If you believe you have found a security issue, write to [SECURITY EMAIL]. [DISCLOSURE POLICY]

Questions

For security questionnaires or more detail, write to [SECURITY EMAIL].