Trust
Trust Center
Security, compliance, and privacy are foundational to everything we build. This page summarizes our practices, certifications, and commitments.
Security
The EEv3 platform is built on a zero-trust security model. Every request is authenticated, authorized, and audited before execution. Our security practices include:
- Encryption at rest (AES-256) and in transit (TLS 1.3) for all data.
- Network-level isolation between tenant environments with strict firewall rules.
- Role-based access controls with least-privilege principles for all internal systems.
- Automated vulnerability scanning and regular third-party penetration testing.
- Security incident detection with 24/7 on-call engineering response.
- Mandatory security training and background checks for all employees.
For a detailed overview of our security architecture, visit the Enterprise Security page.
Compliance
We maintain the following certifications and compliance programs:
SOC 2 Type II
Annual audit of security, availability, and confidentiality controls.
ISO 27001
Certified information security management system.
GDPR
Full compliance with the General Data Protection Regulation, including Data Processing Agreement.
PCI DSS
Level 1 service provider for payment card data handling.
HIPAA
Business Associate Agreements available for healthcare data compliance.
Privacy
We are committed to protecting the privacy of our customers and their end users. Our privacy commitments include:
- We never sell personal data to third parties.
- Customer Data is owned by the customer and can be exported or deleted at any time.
- We process data only as instructed by our customers, in accordance with our Data Processing Agreement.
- We support data subject rights including access, rectification, erasure, and portability.
- Our sub-processor list is transparent and updated with 30 days' notice before changes.
Read our full Privacy Policy and Data Processing Agreement.
Infrastructure
The EEv3 platform runs on enterprise-grade infrastructure designed for reliability, performance, and security:
- Multi-region deployment across North America, Europe, and Asia-Pacific for low-latency global access.
- Automated failover and redundancy at every layer of the stack.
- All data encrypted at rest and in transit, with customer-managed encryption keys available on Enterprise plans.
- Continuous monitoring with real-time alerting for performance, availability, and security anomalies.
- 99.99% uptime SLA backed by financial credits for qualifying plans.
Incident Response
We maintain a formal incident response program with defined severity levels, escalation paths, and communication protocols:
- Severity 1 (Critical): initial response within 15 minutes, status updates every 30 minutes until resolved.
- Severity 2 (High): initial response within 1 hour, status updates every 2 hours.
- Severity 3 (Medium): initial response within 4 hours, resolution within 1 business day.
- Severity 4 (Low): initial response within 1 business day, resolution within 5 business days.
All incidents are followed by a root cause analysis and a published post-mortem for Severity 1 and 2 events. Real-time status is available on our Status page.
Contact
For security concerns, report vulnerabilities to security@vertexstudio.dev. For compliance inquiries or to request our SOC 2 report, contact compliance@vertexstudio.dev.