Vexavexa

Security Overview

Last updated: September 5, 2026

Model

Single-tenant logic per workspace; multi-tenant infrastructure on IaaS.

Regions

All hosting is in Seattle, Washington, USA — Akamai Connected Cloud (Linode) region us-sea. This covers the Kubernetes cluster, the managed PostgreSQL database and the object-storage buckets holding recordings.

We do not currently offer EEA or UK hosting. Speech-to-text is performed by Cloudflare Workers AI on Cloudflare's global network. The full list is on /legal/subprocessors.

Data at rest

Stored on encrypted volumes provided by our IaaS. We do not offer end-to-end encryption.

Data in transit

HTTPS/TLS for all public endpoints.

Access controls

Minimal production access; MFA required; role-based; access limited to operational need and logged.

Secure development

The codebase is open-source and accepts community contributions. We use code review, CI checks, and dependency scanning before deployment. Security issues can be reported via /.well-known/security.txt.

Data minimization

Meetings are recorded by default and the audio is stored in our object storage. Send recording_enabled: false when you request a bot to run that meeting without recording. Transcripts are retained until deleted. System logs avoid sensitive payloads where feasible.

Backups

Infrastructure resilience (e.g., replicas) only. No customer-restorable backups of transcripts; you must export/retain copies.

Deletion

Deletion of completed meetings is currently a manual request. The delete endpoint removes a meeting only before the bot starts; it does not erase completed transcripts or stored recordings. Email info@vexa.ai with the meetings or the account to erase and we will action it. Residual copies may persist briefly in logs or caches until overwritten. Self-service deletion of completed meeting data is in development; this page will be updated when it ships.

Incident response

24/7 monitoring; triage, containment, and customer comms. Breach notices per DPA/Privacy.

Vulnerability disclosure

Email info@vexa.ai or use /.well-known/security.txt. No bug-bounty yet.

Employee & devices

Minimal staff; security training; patched OS; full-disk encryption; least-privilege.

Compliance

No certification claims. We follow reasonable industry practices appropriate for an early-stage SaaS.

Contact

For security-related questions, please contact us at: info@vexa.ai