Security & audit

Your documents carry pricing and means & methods. Vest keeps them yours, locked down by design. This page shows how that works, with sample data.

How your data is protected

Private to your company

Your documents are visible to your team and no one else. Not other customers, not anyone.

Server-enforced access

If you can't open a project, Vest can't search it or cite it for you. Revoke access once and the AI loses it too.

Cited or silent

Every answer shows its source. No source, no answer. Vest won't guess.

No training on your data

Your documents, questions and answers never train anyone's models, including ours.

US processing

Storage, backups and AI calls stay in US regions, with per-company encryption keys in place before your first document is uploaded.

Access you control

Every person has their own account and sees only their projects. Company SSO with MFA lands with pilot partners.

Complianceour posture, plainly
Only what's true today
We never claim a certification we don't hold. Certifications like SOC 2 are pursued when our customers' contracts call for them, and every gap we share comes with a date.
Security packet on request
Pilot partners get our written security summary: what's built, what's coming, and the dated plan for each gap.
Audit logdesign preview · sample rows
WhenActorEventProjectReference
Jul 1 · 2:14 PMDaniel ReyesQuestion answered: 2 citations returnedNorthgateconv_08f3 · msg_1a42
Jul 1 · 2:14 PMVestCitations validated: 2 of 2 present in retrieved evidenceNorthgatemsg_1a42
Jul 1 · 2:01 PMMaria ChenDocument marked superseded: A9.2.1 Rev 1Northgatedoc_4410
Jul 1 · 1:59 PMVestDocument processed: 9 pages, ready for answersNorthgatedoc_5521
Jul 1 · 1:58 PMMaria ChenDocument uploaded: Addendum 02.pdfNorthgatedoc_5521
Jul 1 · 8:32 AMDaniel ReyesSigned insession_77c1
Jun 30 · 4:47 PMT. AlvarezOPERATORAccess-review report exported: operator action, customer-visibleAllexport_9f12
Jun 30 · 9:03 AMPriya PatelProject access granted by Project Admin M. ChenNorthgategrant_3b90
Who can see what
Project-level access
One check gates viewing, search and citations.
Two roles
Admins manage access and documents. Members view and ask.
Database backstop
Even a software bug can't leak one project into another.
Operator discipline
We touch your data only for support you approve, and it's logged above.
The log is designed to store references, never document content, and to be append-only. Nothing can be edited or removed, including by us. Ask us for the current security packet.