1. Overview
This page is a public summary of Vectrel's trust posture for prospective clients, partners, and procurement stakeholders. It is meant to support early diligence conversations, not replace engagement-specific security, privacy, or contracting discussions.
The details on this page focus on Vectrel's public website, public business-development flows, and the general delivery posture reflected in our current offerings. Project-specific architectures, data flows, and contractual obligations are scoped separately with clients.
2. Delivery and deployment posture
Vectrel supports a mix of advisory, build, integration, and ongoing-support work. The delivery model depends on the problem we are solving, the client's existing stack, and the operational requirements of the engagement.
Advisory and roadmap work
Some engagements are strategy-first: readiness work, workflow analysis, architecture decisions, and phased implementation planning.
Client-environment delivery
Where appropriate, Vectrel can design and build systems intended to run inside client-managed infrastructure or alongside client-owned systems.
Vectrel-managed components
For public web experiences or other scoped deliverables, some components may rely on vendor-managed infrastructure selected for the engagement.
Mixed architectures
Many projects involve a blend of client systems, third-party services, and custom application layers, with responsibility boundaries documented during contracting.
Where a project involves client-managed environments, existing systems, or regulated data concerns, the final deployment model and responsibility boundaries are defined during solution design and contracting.
3. Public-site security posture
Vectrel's public site uses HTTPS/TLS, managed hosting, rate-limiting controls, and vendor-managed infrastructure to support the website, intake flows, AI assistant, careers submissions, and scheduling interactions.
We also use operational controls such as access-restricted backend systems and abuse-prevention measures for public endpoints. Like any internet-facing system, the public site is not risk-free, so we do not encourage prospects to send highly sensitive or regulated data through public forms or the public assistant before scope and handling expectations are agreed.
4. AI governance and provider use
Vectrel's work may involve choosing among model providers, inference vendors, and retrieval or workflow patterns based on the requirements of the use case. We do not treat AI tooling as a one-size-fits-all layer.
On the public site, our assistant uses third-party AI infrastructure for inference and embeddings. More broadly, for client work we evaluate tradeoffs such as provider fit, infrastructure constraints, evaluation quality, routing, and operational controls as part of solution design.
Human judgment remains part of the delivery process. We use validation, review, and implementation-specific guardrails where appropriate rather than assuming model output should be trusted without context.
5. Public-site subprocessors
The list below reflects the primary vendors used in Vectrel's current public-site flows. It is not a substitute for an engagement-specific vendor or architecture review, which may vary by project.
Vercel
Public-site hosting, deployment, and web analytics
Supabase
Public-site data storage, file storage, search/retrieval support, and operational records
Inngest
Workflow and event processing tied to intake and internal follow-up
Resend
Transactional and notification email delivery
OpenRouter
AI inference and embeddings for the public assistant, with possible routing to underlying model providers
Cal.com
Discovery-call scheduling and booking
Upstash
Rate limiting and abuse-prevention controls on public APIs
6. Regulated and sensitive-data posture
Vectrel works on systems that may touch operationally sensitive or domain-specific business workflows, including work in environments where data-handling requirements matter. That does not mean the public site is the correct channel for transmitting regulated data.
If a potential engagement involves sensitive, regulated, or contractually constrained data, we address those requirements explicitly during diligence and contracting. That includes scoping the delivery model, determining appropriate handling boundaries, and documenting responsibilities in the relevant project agreements.
7. Procurement and contracting
For serious opportunities, Vectrel can support procurement-oriented conversations that are tied to the actual project being evaluated.
Common diligence topics
- Security and architecture conversations during evaluation
- NDA and confidentiality discussions where appropriate
- Data-processing and vendor-footprint discussions tied to the actual engagement
- Scope-specific diligence for AI, automation, and workflow integrations
Availability of specific documents or contract terms depends on the engagement, the data involved, and the commercial relationship being proposed. This page should not be read as a public promise of any certification, addendum, or data-handling commitment for every project.
8. Security and trust contact
If you need to discuss security, privacy, vendor footprint, or diligence questions in the context of a prospective engagement, contact us at hello@vectrel.ai or start a project conversation through the intake flow.