Security

How Vektor protects your data

Vektor uses layered controls across identity, data access, sensitive fields, signing evidence, transport, and infrastructure. This page describes the controls in place without claiming certifications Vektor does not hold.

Authentication

Clerk manages authentication for Vektor accounts, including the identity layer used to sign users in and associate them with their organizations.

Organization-scoped access

All customer data is protected by organization-scoped row-level security. Database access policies restrict customer records to the organization that owns them.

Stored bank details

Stored bank details are encrypted with AES-256-GCM. Vektor displays only the last four digits of those details in the product.

Signing evidence

Signing evidence is SHA-256 hash-chained, and signing activity is recorded as append-only audit events. This preserves an ordered evidence trail for packet activity.

Data in transit

Connections to Vektor use TLS to protect data in transit between users and the service.

Infrastructure

Vektor runs on Vercel, Supabase, and Fly.io. Each provider operates part of the application, data, or document-processing infrastructure.

To report a security concern responsibly, use the site's contact page.