Security & Trust

Your requirements carry real context. Here’s exactly how we treat them.

User stories describe your product, your customers, and your plans. Vindex reads them to score them — nothing more. This page lists what we do with your data, stated plainly enough to hold us to.

  • Demo uploads live for 24 hours, then they're gone

    CSV files uploaded to the public evaluate page are retained for 24 hours and deleted automatically by a database TTL index. No CSV contents are ever written to the filesystem. Scores are stored in the Vindex Data Platform, scoped to the customer they belong to.

  • Every customer's data is isolated

    Each customer's data is logically separated and scoped by customer ID, resolved to the company at query time. Cross-company records are never exposed — portal endpoints return a 404 for any score outside the caller's company, not a permissions error that confirms the record exists.

  • We don't train models on your data

    Your stories are processed only to produce a score. They are not retained long-term for training and they don't improve anyone else's results.

  • BAA available for regulated teams

    Healthcare and other regulated customers can request a Business Associate Agreement. Talk to the team and we'll get it in front of you.

  • SOC 2 is on the compliance roadmap

    We're not going to show you a badge we don't have. SOC 2 is on the roadmap; current status and timeline are available on request.

  • Model internals stay internal

    Model configuration metadata — including temperature — is always excluded from API responses and callback payloads. Integrations see scores and findings, not model plumbing.

Everything on this page is current practice, not aspiration. As additional security documentation is verified — compliance reports, architecture details — it will be published here. If you need something that isn’t listed yet, ask us directly.

For security reviewers

Need a BAA, SOC 2 status, or answers for a vendor review?

Send us your security questionnaire or ask about the compliance roadmap — the team answers these directly.