Security & Trust
A public overview of how Vectrel approaches delivery, AI tooling, vendor use, and diligence conversations for prospective clients.
01
Overview
This page is a public summary of Vectrel's trust posture for prospective clients, partners, and procurement stakeholders. It is meant to support early diligence conversations, not replace engagement-specific security, privacy, or contracting discussions.
The details on this page focus on Vectrel's public website, public business-development flows, and the general delivery posture reflected in our current offerings. Project-specific architectures, data flows, and contractual obligations are scoped separately with clients.
Delivery and deployment posture
Vectrel supports a mix of advisory, build, integration, and ongoing-support work. The delivery model depends on the problem we are solving, the client's existing stack, and the operational requirements of the engagement.
Advisory and roadmap work
Some engagements are strategy-first: readiness work, workflow analysis, architecture decisions, and phased implementation planning.
Client-environment delivery
Where appropriate, Vectrel can design and build systems intended to run inside client-managed infrastructure or alongside client-owned systems.
Vectrel-managed components
For public web experiences or other scoped deliverables, some components may rely on vendor-managed infrastructure selected for the engagement.
Mixed architectures
Many projects involve a blend of client systems, third-party services, and custom application layers, with responsibility boundaries documented during contracting.
The deployment and responsibility model is defined during solution design and contracting. Vectrel can build for client-managed infrastructure, work alongside client-owned systems, or use a documented mixed architecture when managed services are appropriate. Code, data, infrastructure, generated artifacts, and operating responsibilities are addressed separately in the engagement agreement.
A named technical lead is assigned at kickoff.
That lead remains accountable for architecture decisions and working reviews through the delivery period defined in the engagement agreement.
03
Public-site security posture
Vectrel's public site uses HTTPS/TLS, managed hosting, rate-limiting controls, and vendor-managed infrastructure to support the website, intake flows, AI assistant, careers submissions, and scheduling interactions.
We also use operational controls such as access-restricted backend systems and abuse-prevention measures for public endpoints. Like any internet-facing system, the public site is not risk-free, so we do not encourage prospects to send highly sensitive or regulated data through public forms or the public assistant before scope and handling expectations are agreed.
Public-site Google measurement uses Advanced Consent Mode, starting with analytics storage, advertising storage, advertising user data, and ad personalization denied. Before a visitor chooses, Google may receive limited cookieless pings for aggregate, modeled reporting. With consent, we may retain Google click identifiers and use the email supplied in a completed inquiry for enhanced conversion matching. We do not enable ad personalization, and a Global Privacy Control signal prevents the Google tag from loading.
AI governance and provider use
Vectrel's work may involve choosing among model providers, inference vendors, and retrieval or workflow patterns based on the requirements of the use case. We do not treat AI tooling as a one-size-fits-all layer.
On the public site, our assistant uses third-party AI infrastructure for inference and embeddings. More broadly, for client work we evaluate tradeoffs such as provider fit, infrastructure constraints, evaluation quality, routing, and operational controls as part of solution design.
Human judgment remains part of the delivery process. We use validation, review, and implementation-specific guardrails where appropriate rather than assuming model output should be trusted without context.
05
Public-site subprocessors
The list below reflects the primary vendors used in Vectrel's current public-site flows. It is not a substitute for an engagement-specific vendor or architecture review, which may vary by project.
- Vercel
- Public-site hosting, deployment, and Vercel Web Analytics
- Google Analytics 4 and Google Ads for consent-aware usage analytics, traffic attribution, conversion reporting, and consented enhanced conversions
- Supabase
- Public-site data storage, file storage, search/retrieval support, and operational records
- Inngest
- Workflow and event processing tied to intake and internal follow-up
- Resend
- Transactional and notification email delivery
- OpenRouter
- AI inference and embeddings for the public assistant, with possible routing to underlying model providers
- Cal.com
- Discovery-call scheduling and booking
- Upstash
- Rate limiting and abuse-prevention controls on public APIs
Regulated and sensitive-data posture
Vectrel works on systems that may touch operationally sensitive or domain-specific business workflows, including work in environments where data-handling requirements matter. That does not mean the public site is the correct channel for transmitting regulated data.
If a potential engagement involves sensitive, regulated, or contractually constrained data, we address those requirements explicitly during diligence and contracting. That includes scoping the delivery model, determining appropriate handling boundaries, and documenting responsibilities in the relevant project agreements.
07
Procurement and contracting
For serious opportunities, Vectrel can support procurement-oriented conversations that are tied to the actual project being evaluated.
Common diligence topics
01
Security and architecture conversations during evaluation
02
NDA and confidentiality discussions where appropriate
03
Data-processing and vendor-footprint discussions tied to the actual engagement
04
Scope-specific diligence for AI, automation, and workflow integrations
Availability of specific documents or contract terms depends on the engagement, the data involved, and the commercial relationship being proposed. This page should not be read as a public promise of any certification, addendum, or data-handling commitment for every project.
Security & Trust
Security and trust contact
If you need to discuss security, privacy, vendor footprint, or diligence questions in the context of a prospective engagement, contact us at hello@vectrel.ai or start a project conversation through the intake flow.
Start a project