Skip to content
VaultCX

Draft — requires legal review and sign-off before publication. Not legal advice.

Security & Data Protection

Last updated 3 August 2026

Tenant isolation

Every organisation on the platform is fully isolated, with its own data, users, branding and configuration. Isolation is enforced at the data-access layer, not by interface filtering.

Access control

Access is governed by granular role-based permissions with a roles editor and invitation flow. Last-owner protection prevents an organisation from being locked out of its own workspace.

Encryption

Personally identifiable information in contact records is encrypted at rest. All traffic to the platform is served over TLS.

Audit logging

Every significant administrative action is recorded with the acting user and timestamp, supporting governance and compliance review.

Sub-processors and data location

The sub-processor list, hosting region and data residency position must be stated here before publication.

Vulnerability reporting

The disclosure address and response commitment must be stated here before publication.

Data Processing Agreement

A DPA is available on request. The standard DPA text, or a link to it, must be inserted here before publication.