Security & trust

Built to go company-wide. Without the leak.

Everyone asks the same AI. Everyone sees only what they're allowed to. Every answer verified and cited, and anything it can't check is dropped.

What we guarantee.

Every line here is a description of how the system behaves, not a promise about how we feel.

Fail-closed by default

Denied, errored, timed out, or unreachable: four conditions, one outcome. The source is dropped and unverified content is never shown.

Delegate, don't duplicate

Drive is checked live, per file, as the asker, at question time. Gmail visibility follows the thread's participants, recorded at ingest. WhatsApp follows group membership: a group's answers reach only its members. No mirrored copy of your access rules.

Grounded, cited, honest

Answers come only from verified sources, each one named. When nothing relevant survives, the answer is "I don't know."

Questions hashed in the audit log

Audit records store question text only as a one-way hash. Recent conversation context is retained briefly so follow-up questions work.

Two isolation layers

Each customer gets its own vector collection, and every database row carries a tenant filter on top. Nothing crosses companies.

Append-only audit

Every query, permission-check outcome and citation is written to an append-only log, with a 12-month retention target.

Passwordless sign-in

A one-time code or link arrives on the person's own WhatsApp; the work email is just the username. A reported SIM change freezes access instantly, and only an admin who has verified the person can restore it.

Built for India, worded carefully

Designed to run in AWS Mumbai, with the most sensitive analysis region-locked to Bedrock in Mumbai. We don't claim all your data stays in India.

What's connected.

Gmail, Drive and WhatsApp today; Microsoft 365 and Slack are on the roadmap. WhatsApp is both where you ask and a source of answers.

Google DriveConnected
GmailConnected
WhatsAppConnected
Microsoft 365Coming
SlackComing
More comingrequest yours

Questions we get in every review.

Can Vektor see everything in our Google Workspace?
Your admin decides what Vektor connects to. Answers are scoped further: every source behind an answer is checked against what the person asking is allowed to see, and anything unverified is dropped.
What happens if a permission check fails?
Vektor fails closed. If a check is denied, errors, times out, or the source can't be reached, the affected sources are dropped from the answer. Unverified content is never shown.
Does Vektor copy our permissions into its own system?
No. For Drive, Vektor asks Google who can see a file at the moment of the question, as the asker. For Gmail, the people on a thread are recorded when the message is ingested. For WhatsApp, a group's own membership is the rule: answers drawn from a group go only to the people in it. There is no separately maintained copy of your access rules.
Does Vektor read our WhatsApp group chats?
Only the ones you add it to. Your company provisions a dedicated number for Vektor and adds it to the groups you choose. Those conversations work as a source today, and the integration onto WhatsApp's official Groups API is coming soon. Content from a group is shown only to that group's members, and personal chats are never read.
Which languages does it understand?
English, Hindi and Hinglish. Vektor detects the language of the question and replies in kind, including mid-sentence code-switching.
Are you SOC 2 certified?
Not yet. SOC 2 is on our roadmap, not on our wall. If a certification matters to your review, ask us where it stands and we'll answer honestly.
Where does our data run?
Vektor is designed to run in AWS Mumbai, and the most sensitive analysis is region-locked to Bedrock in Mumbai. We don't claim that all your data stays in India.
What does Vektor store about the questions people ask?
In the audit log, question text is stored only as a one-way hash. Recent conversation context is retained briefly so follow-up questions work. Every query, permission-check outcome and citation is written to that append-only log, with a 12-month retention target.

Put your hardest question to us first.

Bring your security review, your IT lead, or just your doubts. We'll show you exactly how each answer is checked.

Request a demo