Security Overview
Last updated: September 5, 2026
Model
Single-tenant logic per workspace; multi-tenant infrastructure on IaaS.
Regions
All hosting is in Seattle, Washington, USA — Akamai Connected Cloud (Linode) region us-sea. This covers the Kubernetes cluster, the managed PostgreSQL database and the object-storage buckets holding recordings.
We do not currently offer EEA or UK hosting. Speech-to-text is performed by Cloudflare Workers AI on Cloudflare's global network. The full list is on /legal/subprocessors.
Data at rest
Stored on encrypted volumes provided by our IaaS. We do not offer end-to-end encryption.
Data in transit
HTTPS/TLS for all public endpoints.
Access controls
Minimal production access; MFA required; role-based; access limited to operational need and logged.
Secure development
The codebase is open-source and accepts community contributions. We use code review, CI checks, and dependency scanning before deployment. Security issues can be reported via /.well-known/security.txt.
Data minimization
Meetings are recorded by default and the audio is stored in our object storage. Send recording_enabled: false when you request a bot to run that meeting without recording. Transcripts are retained until deleted. System logs avoid sensitive payloads where feasible.
Backups
Infrastructure resilience (e.g., replicas) only. No customer-restorable backups of transcripts; you must export/retain copies.
Deletion
Deletion of completed meetings is currently a manual request. The delete endpoint removes a meeting only before the bot starts; it does not erase completed transcripts or stored recordings. Email info@vexa.ai with the meetings or the account to erase and we will action it. Residual copies may persist briefly in logs or caches until overwritten. Self-service deletion of completed meeting data is in development; this page will be updated when it ships.
Incident response
24/7 monitoring; triage, containment, and customer comms. Breach notices per DPA/Privacy.
Vulnerability disclosure
Email info@vexa.ai or use /.well-known/security.txt. No bug-bounty yet.
Employee & devices
Minimal staff; security training; patched OS; full-disk encryption; least-privilege.
Compliance
No certification claims. We follow reasonable industry practices appropriate for an early-stage SaaS.
Contact
For security-related questions, please contact us at: info@vexa.ai